56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.855 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2025-52451 | HIGH 8.5 | tableau tableau_server Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3 | 0.2% | — |
| CVE-2025-52450 | MED 6.5 | tableau tableau_server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (abdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal.This issue affects Tableau Serv | 0.4% | — |
| CVE-2025-52449 | HIGH 8.5 | tableau tableau_server Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alternative Execution Due to Deceptive Filenames (RCE). This issue affects Tableau Server: before 2025.1.3 | 0.2% | — |
| CVE-2025-52448 | HIGH 8.1 | tableau tableau_server Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Server: | 0.3% | — |
| CVE-2025-52447 | HIGH 8.1 | tableau tableau_server Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Se | 0.4% | — |
| CVE-2025-52446 | HIGH 8.0 | tableau tableau_server Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulation (data access to the production database cluster).This issue affects Tableau Server: before 2025.1. | 0.2% | — |
| CVE-2025-52436 | HIGH 8.8 | fortinet fortisandbox An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all ver | 6.3% | — |
| CVE-2025-52435 | HIGH 7.5 | apache nimble J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to | 0.2% | — |
| CVE-2025-52434 | HIGH 7.5 | apache tomcat Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue aff | 1.9% | — |
| CVE-2025-5180 | HIGH 7.0 | wondershare filmora A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue is some unknown functionality in the library CRYPTBASE.dll of the file NFWCHK.exe of the component Installer. The manipulation leads to unc | 0.3% | — |
| CVE-2025-50213 | CRIT 9.8 | apache apache-airflow-providers-snowflake Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were ad | 0.6% | — |
| CVE-2025-50177 | HIGH 8.1 | microsoft windows_10_1507 Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | 3.9% | — |
| CVE-2025-50176 | HIGH 7.8 | microsoft windows_11_22h2 Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-50175 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-50174 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-50173 | HIGH 7.8 | microsoft windows_10_1507 Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-50172 | MED 6.5 | microsoft windows_10_1809 Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network. | 1.4% | — |
| CVE-2025-50171 | CRIT 9.1 | microsoft windows_server_2022 Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network. | 1.0% | — |
| CVE-2025-50170 | HIGH 7.8 | microsoft windows_10_1809 Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-50169 | HIGH 7.5 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-50168 | HIGH 7.8 | microsoft windows_11_22h2 Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2025-50167 | HIGH 7.0 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-50166 | MED 6.5 | microsoft windows_10_1507 Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2025-50165 | CRIT 9.8 | microsoft windows_11_24h2 Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | 9.5% | — |
| CVE-2025-50164 | HIGH 8.0 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.8% | — |