IT
56.950 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.950 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2025-33050 HIGH 7.5 microsoft windows_server_2016 Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. 1.6%
CVE-2025-33042 HIGH 7.3 apache avro Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are r 0.6%
CVE-2025-33014 MED 5.4 ibm sterling_b2b_integrator IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or p 0.2%
CVE-2025-32932 MED 6.5 fortinet fortisoar An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versio 0.2%
CVE-2025-32915 MED 5.5 checkmk checkmk Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data. 0.1%
CVE-2025-32897 CRIT 9.8 apache seata Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 definition is too narrow. This issue affects Apache Seata (incubatin 1.7%
CVE-2025-32896 MED 6.5 apache seatunnel # Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized users can access `/hazelcast/rest/maps/submit-job` to submit job. An attacker can set extra params in mysql url 1.1%
CVE-2025-32766 MED 6.4 fortinet fortiweb A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands 0.1%
CVE-2025-32726 MED 6.8 microsoft visual_studio_code Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-32725 HIGH 7.5 microsoft windows_server_2016 Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. 1.6%
CVE-2025-32724 HIGH 7.5 microsoft windows_10_1507 Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. 1.6%
CVE-2025-32722 MED 5.5 microsoft windows_10_1507 Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally. 1.0%
CVE-2025-32721 HIGH 7.3 microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-32720 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.6%
CVE-2025-32719 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-32718 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-32717 HIGH 8.4 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-32716 HIGH 7.8 microsoft windows_10_1507 Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-32715 MED 6.5 microsoft remote_desktop_client Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. 1.3%
CVE-2025-32714 HIGH 7.8 microsoft windows_10_1507 Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally. 1.2%
CVE-2025-32713 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0.7%
CVE-2025-32712 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-32711 CRIT 9.3 microsoft 365_copilot Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. 8.0%
CVE-2025-32710 HIGH 8.1 microsoft windows_server_2008 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2025-32707 HIGH 7.8 microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. 0.5%