IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2025-54903 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54902 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54900 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54899 HIGH 7.8 microsoft 365_apps Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54898 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54896 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54550 HIGH 8.1 apache airflow The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be exploited to allow UI user who had access to modify XComs to perform arbitrary execution of code on the worker. S 0.6%
CVE-2025-48823 MED 5.9 microsoft windows_10_1507 Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network. 0.6%
CVE-2025-39688 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid() The pynfs DELEG8 test fails when run against nfsd. It acquires a delegation and then lets the lease time out. It then 0.6%
CVE-2025-22859 MED 5.3 fortinet forticlientems A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests. 0.6%
CVE-2024-43633 MED 6.5 microsoft windows_11_22h2 Windows Hyper-V Denial of Service Vulnerability 0.6%
CVE-2024-39928 HIGH 7.5 apache linkis In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the Token when starting Py4j uses the Commons Lang's RandomStringUtils. Users are recommended to upgrade to version 1.6.0, which fixes this issue. 0.6%
CVE-2024-37982 MED 6.7 microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability 0.6%
CVE-2024-37979 MED 6.7 microsoft windows_server_2012 Windows Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2023-20115 MED 5.4 cisco nx-os A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode could allow an authenticated, remote attacker to download or overwrite files from the underlying operating system of an aff 0.6%
CVE-2023-0932 HIGH 8.8 google chrome Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Hig 0.6%
CVE-2022-36772 MED 6.5 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user. 0.6%
CVE-2026-57105 HIGH 8.0 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.6%
CVE-2025-54293 MED 6.5 canonical lxd Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symbolic links. 0.6%
CVE-2024-50046 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSv4: Prevent NULL-pointer dereference in nfs42_complete_copies() On the node of an NFS client, some files saved in the mountpoint of the NFS server were copied to another location of the s 0.6%
CVE-2024-30071 MED 4.7 microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.6%
CVE-2024-26239 HIGH 7.8 microsoft windows_10_1507 Windows Telephony Server Elevation of Privilege Vulnerability 0.6%
CVE-2024-0083 MED 6.5 nvidia chatrtx NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause a cross-site scripting error by network by running malicious scripts in users' browsers. A successful exploit of this vulnerability might lead to code execution, denial 0.6%
CVE-2023-23411 MED 6.5 microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability 0.6%
CVE-2023-21678 HIGH 7.8 microsoft windows_10_1607 Windows Print Spooler Elevation of Privilege Vulnerability 0.6%