56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.855 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2025-49124 | HIGH 8.4 | apache tomcat Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 thro | 0.3% | — |
| CVE-2025-48989 | HIGH 7.5 | apache tomcat Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, | 3.5% | — |
| CVE-2025-48988 | HIGH 7.5 | apache tomcat Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time th | 57.0% | — |
| CVE-2025-48977 | MED 6.5 | apache ignite Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can read any file on the server with "cmd=log" command and a log path crafted in a certain way. This issue affects Apache Ignite: from 2.0.0 through 2.17.0. Users a | 0.5% | — |
| CVE-2025-48976 | HIGH 7.5 | apache commons_fileupload Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrad | 67.8% | — |
| CVE-2025-48924 | MED 5.3 | apache commons_lang Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can th | 2.3% | — |
| CVE-2025-48913 | CRIT 9.8 | apache cxf If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are r | 0.8% | — |
| CVE-2025-48912 | MED 6.5 | apache superset An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unauthorized a | 0.7% | — |
| CVE-2025-48840 | MED 5.3 | fortinet fortiweb An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unauthenticated attacker to bypass hostname restrictions via a sp | 0.5% | — |
| CVE-2025-48839 | MED 6.6 | fortinet fortiadc An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to execute arbitrary code via specially craft | 0.4% | — |
| CVE-2025-48824 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2025-48823 | MED 5.9 | microsoft windows_10_1507 Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2025-48822 | HIGH 8.6 | microsoft windows_10_1607 Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-48821 | HIGH 7.1 | microsoft windows_10_1507 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network. | 0.4% | — |
| CVE-2025-48820 | HIGH 7.8 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-48819 | HIGH 7.1 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network. | 0.3% | — |
| CVE-2025-48818 | MED 6.8 | microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.4% | — |
| CVE-2025-48817 | HIGH 8.8 | microsoft remote_desktop_client Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-48816 | HIGH 7.8 | microsoft windows_10_1507 Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-48815 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows SSDP Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-48814 | HIGH 7.5 | microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network. | 1.0% | — |
| CVE-2025-48813 | MED 6.3 | microsoft windows_10_1809 Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally. | 0.2% | — |
| CVE-2025-48812 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-48811 | MED 6.7 | microsoft windows_10_1507 Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-48810 | MED 5.5 | microsoft windows_11_24h2 Processor optimization removal or modification of security-critical code in Windows Secure Kernel Mode allows an authorized attacker to disclose information locally. | 0.5% | — |