56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.855 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2025-53844 | HIGH 8.8 | fortinet fortios A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets. | 0.6% | — |
| CVE-2025-53843 | HIGH 7.5 | fortinet fortios A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to execute unauthorized code or commands via speciall | 0.6% | — |
| CVE-2025-53810 | MED 6.7 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-53809 | MED 6.5 | microsoft windows_11_24h2 Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. | 1.5% | — |
| CVE-2025-53808 | MED 6.7 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-53807 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-53806 | MED 6.5 | microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.2% | — |
| CVE-2025-53805 | HIGH 7.5 | microsoft windows_11_22h2 Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network. | 1.4% | — |
| CVE-2025-53804 | MED 5.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-53803 | MED 5.5 | microsoft windows_10_1507 Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-53802 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53801 | HIGH 7.8 | microsoft windows_10_1507 Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53800 | HIGH 7.8 | microsoft windows_10_1607 No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-53799 | MED 5.5 | microsoft 365_copilot Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally. | 0.8% | — |
| CVE-2025-53798 | MED 6.5 | microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.2% | — |
| CVE-2025-53797 | MED 6.5 | microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.2% | — |
| CVE-2025-53796 | MED 6.5 | microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.2% | — |
| CVE-2025-53795 | CRIT 9.1 | microsoft pc_manager Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2025-53793 | HIGH 7.5 | microsoft azure_stack_hub Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2025-53792 | CRIT 9.1 | microsoft azure_portal Azure Portal Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2025-53791 | MED 4.7 | microsoft edge_chromium Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | 0.4% | — |
| CVE-2025-53789 | HIGH 7.8 | microsoft windows_10_1507 Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53788 | HIGH 7.0 | microsoft windows_subsystem_for_linux Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-53787 | HIGH 8.2 | microsoft 365_copilot_chat Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | 0.7% | — |
| CVE-2025-53786 | HIGH 8.0 | microsoft exchange_server On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following furt | 7.4% | — |