57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-67706 | MED 5.6 | esri arcgis_server ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the server’s architecture en | 0.4% | — |
| CVE-2025-60721 | HIGH 7.8 | microsoft windows_11_24h2 Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-60716 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-59514 | HIGH 7.8 | microsoft windows_10_1607 Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53789 | HIGH 7.8 | microsoft windows_10_1507 Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53721 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53681 | HIGH 7.2 | fortinet fortimail An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privil | 0.4% | — |
| CVE-2025-53142 | HIGH 7.0 | microsoft windows_11_22h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53140 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53133 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-22855 | LOW 2.7 | fortinet forticlientems An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code. | 0.4% | — |
| CVE-2025-21720 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfrm: delete intermediate secpath entry in packet offload mode Packets handled by hardware have added secpath as a way to inform XFRM core code that this path was already handled. That secpa | 0.4% | — |
| CVE-2025-1992 | MED 5.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after us | 0.4% | — |
| CVE-2024-52967 | LOW 3.5 | fortinet fortiportal An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attacker to execute unauthorized code or commands via html injection. | 0.4% | — |
| CVE-2024-20377 | MED 5.4 | cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due t | 0.4% | — |
| CVE-2023-47073 | HIGH 7.8 | adobe after_effects Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 0.4% | — |
| CVE-2023-47070 | HIGH 7.8 | adobe after_effects Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 0.4% | — |
| CVE-2023-33155 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2022-50472 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: IB/mad: Don't call to function that might sleep while in atomic context Tracepoints are not allowed to sleep, as such the following splat is generated due to call to ib_query_pkey() in atomi | 0.4% | — |
| CVE-2022-43949 | MED 6.2 | fortinet fortisiem A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated hashing methods. | 0.4% | — |
| CVE-2022-28390 | HIGH 7.8 | debian debian_linux ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free. | 0.4% | — |
| CVE-2020-3974 | HIGH 7.8 | vmware fusion VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitatio | 0.4% | — |
| CVE-2020-12362 | HIGH 7.8 | intel graphics_drivers Integer overflow in the firmware for some Intel(R) Graphics Drivers for Windows * before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable an escalation of privilege via local access. | 0.4% | — |
| CVE-2020-10690 | MED 6.5 | canonical ubuntu_linux There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. | 0.4% | — |
| CVE-2017-6267 | MED 5.5 | nvidia gpu_driver NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where an incorrect initialization of internal objects can cause an infinite loop which may lead to a denial of service. | 0.4% | — |