58.135 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.135 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-59273 | HIGH 7.3 | microsoft azure_event_grid Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2025-59118 | HIGH 7.3 | apache ofbiz Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the issue. | 1.6% | — |
| CVE-2025-55322 | HIGH 7.3 | microsoft omniparser Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network. | 0.4% | — |
| CVE-2025-55310 | HIGH 7.3 | foxit pdf_editor An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. An attacker able to alter or replace the static HTML files used by the StartPage feature can cause the application to load malicious or compromised conten | 0.1% | — |
| CVE-2025-55247 | HIGH 7.3 | microsoft .net Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-55240 | HIGH 7.3 | microsoft visual_studio_2017 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55236 | HIGH 7.3 | microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-54911 | HIGH 7.3 | microsoft windows_10_1507 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-54116 | HIGH 7.3 | microsoft windows_10_1507 Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-50161 | HIGH 7.3 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-50159 | HIGH 7.3 | microsoft windows_10_1507 Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-49682 | HIGH 7.3 | microsoft windows_10_21h2 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-49680 | HIGH 7.3 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally. | 0.5% | — |
| CVE-2025-48500 | HIGH 7.3 | f5 big-ip_access_policy_manager A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer. Note: Software versions which ha | 0.1% | — |
| CVE-2025-46701 | HIGH 7.3 | apache tomcat Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0 | 2.9% | — |
| CVE-2025-41231 | HIGH 7.3 | vmware cloud_foundation VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information. | 0.2% | — |
| CVE-2025-39960 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: gpiolib: acpi: initialize acpi_gpio_info struct Since commit 7c010d463372 ("gpiolib: acpi: Make sure we fill struct acpi_gpio_info"), uninitialized acpi_gpio_info struct are passed to __acpi | 0.2% | — |
| CVE-2025-39798 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: NFS: Fix the setting of capabilities when automounting a new filesystem Capabilities cannot be inherited when we cross into a new filesystem. They need to be reset to the minimal defaults, a | 0.3% | — |
| CVE-2025-39789 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: x86/aegis - Add missing error checks The skcipher_walk functions can allocate memory and can fail, so checking for errors is necessary. | 0.1% | — |
| CVE-2025-39738 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: btrfs: do not allow relocation of partially dropped subvolumes [BUG] There is an internal report that balance triggered transaction abort, with the following call trace: item 85 key (5945 | 0.2% | — |
| CVE-2025-39694 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: s390/sclp: Fix SCCB present check Tracing code called by the SCLP interrupt handler contains early exits if the SCCB address associated with an interrupt is NULL. This check is performed aft | 0.2% | — |
| CVE-2025-38687 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: comedi: fix race between polling and detaching syzbot reports a use-after-free in comedi in the below link, which is due to comedi gladly removing the allocated async area even though poll r | 0.1% | — |
| CVE-2025-38679 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: media: venus: Fix OOB read due to missing payload bound check Currently, The event_seq_changed() handler processes a variable number of properties sent by the firmware. The number of propert | 0.2% | — |
| CVE-2025-38657 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: mcc: prevent shift wrapping in rtw89_core_mlsr_switch() The "link_id" value comes from the user via debugfs. If it's larger than BITS_PER_LONG then that would result in shift w | 0.1% | — |
| CVE-2025-38652 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in devs.path - touch /mnt/f2fs/012345678901234567890123456789012345678901234567890123 - truncate -s $((1024*1024*1024)) \ /mnt/f2fs/01234567890123 | 0.2% | — |