56.950 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.950 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2025-33050 | HIGH 7.5 | microsoft windows_server_2016 Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.6% | — |
| CVE-2025-33042 | HIGH 7.3 | apache avro Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are r | 0.6% | — |
| CVE-2025-33014 | MED 5.4 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or p | 0.2% | — |
| CVE-2025-32932 | MED 6.5 | fortinet fortisoar An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versio | 0.2% | — |
| CVE-2025-32915 | MED 5.5 | checkmk checkmk Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data. | 0.1% | — |
| CVE-2025-32897 | CRIT 9.8 | apache seata Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 definition is too narrow. This issue affects Apache Seata (incubatin | 1.7% | — |
| CVE-2025-32896 | MED 6.5 | apache seatunnel # Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized users can access `/hazelcast/rest/maps/submit-job` to submit job. An attacker can set extra params in mysql url | 1.1% | — |
| CVE-2025-32766 | MED 6.4 | fortinet fortiweb A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands | 0.1% | — |
| CVE-2025-32726 | MED 6.8 | microsoft visual_studio_code Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-32725 | HIGH 7.5 | microsoft windows_server_2016 Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.6% | — |
| CVE-2025-32724 | HIGH 7.5 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | 1.6% | — |
| CVE-2025-32722 | MED 5.5 | microsoft windows_10_1507 Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally. | 1.0% | — |
| CVE-2025-32721 | HIGH 7.3 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-32720 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-32719 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-32718 | HIGH 7.8 | microsoft windows_10_1507 Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-32717 | HIGH 8.4 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-32716 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-32715 | MED 6.5 | microsoft remote_desktop_client Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2025-32714 | HIGH 7.8 | microsoft windows_10_1507 Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally. | 1.2% | — |
| CVE-2025-32713 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2025-32712 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-32711 | CRIT 9.3 | microsoft 365_copilot Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 8.0% | — |
| CVE-2025-32710 | HIGH 8.1 | microsoft windows_server_2008 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-32707 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0.5% | — |