57.023 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
57.023 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2025-21201 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Server Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2025-21200 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2025-21199 | MED 6.7 | microsoft azure_agent Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-21198 | CRIT 9.0 | microsoft hpc_pack_2016 Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2025-21197 | MED 6.5 | microsoft windows_10_1507 Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content. | 2.9% | — |
| CVE-2025-21195 | MED 6.0 | microsoft azure_service_fabric Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-21194 | HIGH 7.1 | microsoft surface_go_2_1901_firmware Microsoft Surface Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2025-21193 | MED 6.5 | microsoft windows_server_2016 Active Directory Federation Server Spoofing Vulnerability | 0.8% | — |
| CVE-2025-21191 | HIGH 7.0 | microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-21190 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2025-21189 | MED 4.3 | microsoft windows_10_1507 MapUrlToZone Security Feature Bypass Vulnerability | 3.0% | — |
| CVE-2025-21188 | MED 6.0 | microsoft azure_network_watcher Azure Network Watcher VM Extension Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-21187 | HIGH 7.8 | microsoft power_automate_for_desktop Microsoft Power Automate Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2025-21186 | HIGH 7.8 | microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2025-21185 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2025-21184 | HIGH 7.0 | microsoft windows_10_1507 Windows Core Messaging Elevation of Privileges Vulnerability | 0.6% | — |
| CVE-2025-21183 | HIGH 7.4 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2025-21182 | HIGH 7.4 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2025-21181 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 3.4% | — |
| CVE-2025-21180 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally. | 0.9% | — |
| CVE-2025-21179 | MED 4.8 | microsoft windows_11_24h2 DHCP Client Service Denial of Service Vulnerability | 0.7% | — |
| CVE-2025-21178 | HIGH 8.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2025-21177 | HIGH 8.7 | microsoft dynamics_365_sales Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2025-21176 | HIGH 8.8 | microsoft .net .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2025-21174 | HIGH 7.5 | microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | 1.9% | — |