56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.832 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2025-57823 | LOW 2.7 | fortinet fortiauthenticator A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at lea | 0.2% | — |
| CVE-2025-5781 | MED 5.2 | hitachi configuration_manager Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; | 0.1% | — |
| CVE-2025-57780 | HIGH 8.8 | f5 f5os-a A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. Note: Software versions which have reached E | 0.2% | — |
| CVE-2025-57741 | HIGH 7.8 | fortinet forticlient An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local attacker to run arbitrary code or commands via LaunchDaemon hijacking. | 0.1% | — |
| CVE-2025-57740 | HIGH 7.5 | fortinet fortios An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions | 0.6% | — |
| CVE-2025-57738 | HIGH 7.2 | apache syncope Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being p | 23.1% | — |
| CVE-2025-57735 | CRIT 9.1 | apache airflow When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who ar | 0.7% | — |
| CVE-2025-57716 | MED 6.7 | fortinet forticlient An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClien | 0.2% | — |
| CVE-2025-55754 | CRIT 9.6 | apache tomcat Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape | 10.1% | — |
| CVE-2025-55753 | HIGH 7.5 | apache http_server An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. T | 0.4% | — |
| CVE-2025-55752 | HIGH 7.5 | apache tomcat Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query paramete | 66.5% | — |
| CVE-2025-55717 | MED 4.0 | fortinet fortimail A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiR | 0.1% | — |
| CVE-2025-55701 | HIGH 7.8 | microsoft windows_10_1507 Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55700 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2025-55699 | MED 5.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-55698 | HIGH 7.7 | microsoft windows_11_24h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network. | 1.1% | — |
| CVE-2025-55697 | HIGH 7.8 | microsoft windows_server_2022_23h2 Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55696 | HIGH 7.8 | microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-55695 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2025-55694 | HIGH 7.8 | microsoft windows_11_24h2 Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | 2.8% | — |
| CVE-2025-55693 | HIGH 7.4 | microsoft windows_11_24h2 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | 1.9% | — |
| CVE-2025-55692 | HIGH 7.8 | microsoft windows_10_1507 Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | 3.2% | — |
| CVE-2025-55691 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55690 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55689 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0.3% | — |