IT
57.056 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2025-0966 HIGH 7.6 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. 0.3%
CVE-2025-0913 MED 5.5 golang go os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink t 0.3%
CVE-2025-0759 LOW 3.3 ibm entirex IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared resource synchronization. 0.1%
CVE-2025-0589 MED 5.3 octopus octopus_server In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API request against two endpoints which would retrieve some data from the associated Active Directory. T 0.4%
CVE-2025-0588 MED 4.9 octopus octopus_server In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all server responses. By submitting a specifically crafted referrer header the user could ensure that all subsequent server responses would return 0.4%
CVE-2025-0539 HIGH 8.8 octopus octopus_server In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially 0.3%
CVE-2025-0526 MED 5.4 octopus octopus_server In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows. 0.3%
CVE-2025-0525 HIGH 7.5 octopus octopus_server In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could provide an adversary with information that may aid in further attacks against the server. 0.4%
CVE-2025-0513 MED 5.4 octopus octopus_server In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the user viewing the error message. 0.2%
CVE-2025-0502 CRIT 9.1 craftercms craftercms Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM allows Directory Indexing, Resource Leak Exposure.This issue affects CrafterCMS: from 4.0.0 before 4.0.8, from 4 0.4%
CVE-2025-0440 MED 6.5 google chrome Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) 0.4%
CVE-2025-0320 HIGH 7.8 citrix secure_access_client Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows 0.1%
CVE-2025-0158 MED 5.5 ibm entirex IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation. 0.1%
CVE-2025-0154 MED 5.3 ibm txseries_for_multiplatforms IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose sensitive information to a remote attacker due to improper neutralization of HTTP headers. 0.4%
CVE-2025-0135 LOW 3.3 paloaltonetworks globalprotect An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and Glob 0.1%
CVE-2025-0130 HIGH 7.5 paloaltonetworks pan-os A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeate 0.4%
CVE-2025-0124 LOW 3.8 paloaltonetworks pan-os An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configura 0.3%
CVE-2025-0120 HIGH 7.0 paloaltonetworks globalprotect A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution require 0.2%
CVE-2025-0118 HIGH 8.0 paloaltonetworks globalprotect A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated use 0.4%
CVE-2025-0114 HIGH 7.5 paloaltonetworks pan-os A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of time. This 0.4%
CVE-2025-0107 CRIT 9.8 paloaltonetworks expedition An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations 78.5%
CVE-2025-0106 MED 5.3 paloaltonetworks expedition A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem. 0.5%
CVE-2025-0105 CRIT 9.1 paloaltonetworks expedition An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem. 13.3%
CVE-2025-0104 MED 6.1 paloaltonetworks expedition A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that al 0.4%
CVE-2025-0103 HIGH 8.8 paloaltonetworks expedition An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers 0.6%