56.950 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.950 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2025-29976 | HIGH 7.8 | microsoft sharepoint_server Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-29975 | HIGH 7.8 | microsoft pc_manager Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-29974 | MED 5.7 | microsoft windows_10_1507 Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network. | 0.7% | — |
| CVE-2025-29973 | HIGH 7.0 | microsoft azure_file_sync Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-29972 | CRIT 9.9 | microsoft azure_storage_resource_provider Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. | 3.2% | — |
| CVE-2025-29971 | HIGH 7.5 | microsoft windows_11_22h2 Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network. | 64.4% | — |
| CVE-2025-29970 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-29969 | HIGH 7.5 | microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2025-29968 | MED 6.5 | microsoft windows_server_2008 Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network. | 1.8% | — |
| CVE-2025-29967 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2025-29966 | HIGH 8.8 | microsoft remote_desktop Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. | 1.4% | — |
| CVE-2025-29964 | HIGH 8.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-29963 | HIGH 8.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-29962 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 14.3% | — |
| CVE-2025-29961 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2025-29960 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.4% | — |
| CVE-2025-29959 | MED 6.5 | microsoft windows_10_1507 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.4% | — |
| CVE-2025-29958 | MED 6.5 | microsoft windows_10_1507 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2025-29957 | MED 6.2 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally. | 0.6% | — |
| CVE-2025-29956 | MED 5.4 | microsoft windows_10_1507 Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2025-29955 | MED 6.2 | microsoft windows_11_24h2 Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally. | 0.5% | — |
| CVE-2025-29954 | MED 5.9 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | 1.4% | — |
| CVE-2025-29953 | CRIT 9.8 | apache activemq_nms_openwire Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unbounded deserializatio | 1.9% | — |
| CVE-2025-29891 | MED 4.8 | apache camel Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4. Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 | 75.1% | — |
| CVE-2025-29868 | MED 6.5 | apache answer Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private | 0.9% | — |