IT
56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.959 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2025-27746 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.8%
CVE-2025-27745 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 1.1%
CVE-2025-27744 HIGH 7.8 microsoft office Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally. 1.1%
CVE-2025-27743 HIGH 7.8 microsoft system_center_data_protection_manager Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. 0.8%
CVE-2025-27742 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally. 0.8%
CVE-2025-27741 HIGH 7.8 microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. 0.8%
CVE-2025-27740 HIGH 8.8 microsoft windows_server_2008 Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network. 3.3%
CVE-2025-27739 HIGH 7.8 microsoft windows_10_1809 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-27738 MED 6.5 microsoft windows_10_1507 Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network. 3.2%
CVE-2025-27737 HIGH 8.6 microsoft windows_10_1507 Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally. 0.7%
CVE-2025-27736 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally. 0.8%
CVE-2025-27735 MED 6.0 microsoft windows_10_1507 Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. 0.4%
CVE-2025-27733 HIGH 7.8 microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. 0.7%
CVE-2025-27732 HIGH 7.0 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-27731 HIGH 7.8 microsoft windows_10_1809 Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-27730 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-27729 HIGH 7.8 microsoft windows_10_21h2 Use after free in Windows Shell allows an unauthorized attacker to execute code locally. 0.8%
CVE-2025-27728 HIGH 7.8 microsoft windows_11_24h2 Out-of-bounds read in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-27727 HIGH 7.8 microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally. 0.9%
CVE-2025-27696 HIGH 8.8 apache superset Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade to version 1.2%
CVE-2025-27636 MED 5.6 apache camel Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from 3.10.0 through <= 3.22.3. Users are recommended to upgrade to version 4.1 80.9%
CVE-2025-27556 MED 5.8 djangoproject django An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are subject to 1.0%
CVE-2025-27555 MED 6.5 apache airflow Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, values of those variables 0.4%
CVE-2025-27553 HIGH 7.5 apache commons_vfs Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved fil 1.4%
CVE-2025-27533 HIGH 7.5 apache activemq Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of 8.6%