56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.959 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2025-26865 | LOW 3.5 | apache ofbiz Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: from 18.12.17 before 18.12.18. It's a regression between 18.12.17 and 18.12.18. In case you use something like that, which | 0.7% | — |
| CVE-2025-26864 | HIGH 7.5 | apache iotdb Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. User | 0.7% | — |
| CVE-2025-26796 | MED 5.4 | apache oozie ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. This issue affects Apache Oozie: all versions. As this project is retired, we do not plan to release a version | 0.5% | — |
| CVE-2025-26795 | HIGH 7.5 | apache iotdb Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommen | 0.7% | — |
| CVE-2025-26688 | HIGH 7.8 | microsoft windows_10_1507 Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-26687 | HIGH 7.5 | microsoft 365_copilot Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2025-26686 | HIGH 7.5 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | 1.5% | — |
| CVE-2025-26685 | MED 6.5 | microsoft defender_for_identity Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network. | 0.7% | — |
| CVE-2025-26684 | MED 6.7 | microsoft defender_for_endpoint External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-26683 | HIGH 8.1 | microsoft azure_playwright Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-26682 | HIGH 7.5 | microsoft asp.net_core Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 1.5% | — |
| CVE-2025-26681 | MED 6.7 | microsoft windows_10_21h2 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-26680 | HIGH 7.5 | microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | 1.8% | — |
| CVE-2025-26679 | HIGH 7.8 | microsoft windows_10_1507 Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-26678 | HIGH 8.4 | microsoft windows_10_1809 Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally. | 0.5% | — |
| CVE-2025-26677 | HIGH 7.5 | microsoft windows_server_2016 Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network. | 1.7% | — |
| CVE-2025-26676 | MED 6.5 | microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.5% | — |
| CVE-2025-26675 | HIGH 7.8 | microsoft windows_10_21h2 Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-26674 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-26673 | HIGH 7.5 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | 2.4% | — |
| CVE-2025-26672 | MED 6.5 | microsoft windows_10_1507 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.6% | — |
| CVE-2025-26671 | HIGH 8.1 | microsoft windows_server_2008 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.2% | — |
| CVE-2025-26670 | HIGH 8.1 | microsoft windows_10_1507 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | 10.4% | — |
| CVE-2025-26669 | HIGH 8.8 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.4% | — |
| CVE-2025-26668 | HIGH 7.5 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1.2% | — |