IT
58.135 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.135 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-38573 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: spi: cs42l43: Property entry should be a null-terminated array The software node does not specify a count of property entries, so the array must be null-terminated. When unterminated, this 0.2%
CVE-2025-38547 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iio: adc: axp20x_adc: Add missing sentinel to AXP717 ADC channel maps The AXP717 ADC channel maps is missing a sentinel entry at the end. This causes a KASAN warning. Add the missing sentin 0.1%
CVE-2025-38508 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: x86/sev: Use TSC_FACTOR for Secure TSC frequency calculation When using Secure TSC, the GUEST_TSC_FREQ MSR reports a frequency based on the nominal P0 frequency, which deviates slightly (typ 0.1%
CVE-2025-38446 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: clk: imx: Fix an out-of-bounds access in dispmix_csr_clk_dev_data When num_parents is 4, __clk_register() occurs an out-of-bounds when accessing parent_names member. Use ARRAY_SIZE() instead 0.2%
CVE-2025-38314 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio-pci: Fix result size returned for the admin command completion The result size returned by virtio_pci_admin_dev_parts_get() is 8 bytes larger than the actual result data size. This oc 0.1%
CVE-2025-38257 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Prevent overflow in size calculation for memdup_user() Number of apqn target list entries contained in 'nr_apqns' variable is determined by userspace via an ioctl call so the resu 0.2%
CVE-2025-38239 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Fix invalid node index On a system with DRAM interleave enabled, out-of-bound access is detected: megaraid_sas 0000:3f:00.0: requested/available msix 128/128 poll_queue 0.2%
CVE-2025-38197 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell_rbu: Fix list usage Pass the correct list head to list_for_each_entry*() when looping through the packet list. Without this patch, reading the packet data via sysfs will 0.2%
CVE-2025-38004 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates The CAN broadcast manager (CAN BCM) can send a sequence of CAN frames via hrtimer. The content and also the length of the sequence can be cha 0.2%
CVE-2025-37931 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: btrfs: adjust subpage bit start based on sectorsize When running machines with 64k page size and a 16k nodesize we started seeing tree log corruption in production. This turned out to be be 0.2%
CVE-2025-35471 HIGH 7.3 conda-forge miniforge conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privile 0.2%
CVE-2025-33230 HIGH 7.3 nvidia cuda_toolkit NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a malicious string to the installation path. A successful exploit of this vulnerability might lead to escalation 1.4%
CVE-2025-33229 HIGH 7.3 nvidia cuda_toolkit NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitrary code with the same privileges as the NVIDIA Nsight Visual Studio Edition Monitor application. A successful exploit of this vulnerability 0.2%
CVE-2025-33042 HIGH 7.3 apache avro Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are r 0.6%
CVE-2025-32721 HIGH 7.3 microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-30661 HIGH 7.3 juniper junos An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processing of Juniper Networks Junos OS allows a local, low-privileged user to install scripts to be executed as root, leading to privilege escalation. A local user wit 0.2%
CVE-2025-30001 HIGH 7.3 apache streampark Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. 0.6%
CVE-2025-29826 HIGH 7.3 microsoft dataverse Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2025-29804 HIGH 7.3 microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. 1.3%
CVE-2025-29803 HIGH 7.3 microsoft sql_server_management_studio Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally. 0.8%
CVE-2025-29802 HIGH 7.3 microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. 0.9%
CVE-2025-29792 HIGH 7.3 microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. 1.1%
CVE-2025-27821 HIGH 7.3 apache hadoop Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. 0.9%
CVE-2025-26631 HIGH 7.3 microsoft visual_studio_code Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-26628 HIGH 7.3 microsoft azure_local_cluster Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally. 1.4%