IT
56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.959 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2025-32717 HIGH 8.4 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-32716 HIGH 7.8 microsoft windows_10_1507 Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-32715 MED 6.5 microsoft remote_desktop_client Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. 1.3%
CVE-2025-32714 HIGH 7.8 microsoft windows_10_1507 Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally. 1.2%
CVE-2025-32713 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0.7%
CVE-2025-32712 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-32711 CRIT 9.3 microsoft 365_copilot Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. 8.0%
CVE-2025-32710 HIGH 8.1 microsoft windows_server_2008 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2025-32707 HIGH 7.8 microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. 0.5%
CVE-2025-32705 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-32704 HIGH 8.4 microsoft 365_apps Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-32703 MED 5.5 microsoft visual_studio_2017 Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-32702 HIGH 7.8 microsoft visual_studio_2019 Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-3221 HIGH 7.5 ibm infosphere_information_server IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. 0.4%
CVE-2025-32098 MED 5.3 samsung magician An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process. 0.2%
CVE-2025-31698 HIGH 7.5 apache traffic_server ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to 0.5%
CVE-2025-31672 MED 5.3 apache poi Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (incl 1.3%
CVE-2025-31651 CRIT 9.8 apache tomcat Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effective 4.0%
CVE-2025-31650 HIGH 7.5 apache tomcat Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfM 59.9%
CVE-2025-31644 HIGH 8.7 f5 big-ip_access_policy_manager When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A s 23.9%
CVE-2025-31514 LOW 2.7 fortinet fortios A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 t 0.3%
CVE-2025-31366 MED 4.7 fortinet fortios An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7 0.4%
CVE-2025-31365 MED 5.8 fortinet forticlient An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user into visit 0.3%
CVE-2025-31104 HIGH 7.2 fortinet fortiadc A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiADC 7.6.0 through 7.6.1, FortiADC 7.4.0 through 7.4.6, FortiADC 7.2.0 through 7.2.7, FortiADC 7.1.0 through 7.1.4, FortiADC 7.0 all vers 1.2%
CVE-2025-30680 HIGH 7.1 trendmicro apex_central A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. Please note: this vulnerability only affects the Sa 0.2%