58.135 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.135 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-38573 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: spi: cs42l43: Property entry should be a null-terminated array The software node does not specify a count of property entries, so the array must be null-terminated. When unterminated, this | 0.2% | — |
| CVE-2025-38547 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iio: adc: axp20x_adc: Add missing sentinel to AXP717 ADC channel maps The AXP717 ADC channel maps is missing a sentinel entry at the end. This causes a KASAN warning. Add the missing sentin | 0.1% | — |
| CVE-2025-38508 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: x86/sev: Use TSC_FACTOR for Secure TSC frequency calculation When using Secure TSC, the GUEST_TSC_FREQ MSR reports a frequency based on the nominal P0 frequency, which deviates slightly (typ | 0.1% | — |
| CVE-2025-38446 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: clk: imx: Fix an out-of-bounds access in dispmix_csr_clk_dev_data When num_parents is 4, __clk_register() occurs an out-of-bounds when accessing parent_names member. Use ARRAY_SIZE() instead | 0.2% | — |
| CVE-2025-38314 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio-pci: Fix result size returned for the admin command completion The result size returned by virtio_pci_admin_dev_parts_get() is 8 bytes larger than the actual result data size. This oc | 0.1% | — |
| CVE-2025-38257 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Prevent overflow in size calculation for memdup_user() Number of apqn target list entries contained in 'nr_apqns' variable is determined by userspace via an ioctl call so the resu | 0.2% | — |
| CVE-2025-38239 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Fix invalid node index On a system with DRAM interleave enabled, out-of-bound access is detected: megaraid_sas 0000:3f:00.0: requested/available msix 128/128 poll_queue | 0.2% | — |
| CVE-2025-38197 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell_rbu: Fix list usage Pass the correct list head to list_for_each_entry*() when looping through the packet list. Without this patch, reading the packet data via sysfs will | 0.2% | — |
| CVE-2025-38004 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates The CAN broadcast manager (CAN BCM) can send a sequence of CAN frames via hrtimer. The content and also the length of the sequence can be cha | 0.2% | — |
| CVE-2025-37931 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: btrfs: adjust subpage bit start based on sectorsize When running machines with 64k page size and a 16k nodesize we started seeing tree log corruption in production. This turned out to be be | 0.2% | — |
| CVE-2025-35471 | HIGH 7.3 | conda-forge miniforge conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privile | 0.2% | — |
| CVE-2025-33230 | HIGH 7.3 | nvidia cuda_toolkit NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a malicious string to the installation path. A successful exploit of this vulnerability might lead to escalation | 1.4% | — |
| CVE-2025-33229 | HIGH 7.3 | nvidia cuda_toolkit NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitrary code with the same privileges as the NVIDIA Nsight Visual Studio Edition Monitor application. A successful exploit of this vulnerability | 0.2% | — |
| CVE-2025-33042 | HIGH 7.3 | apache avro Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are r | 0.6% | — |
| CVE-2025-32721 | HIGH 7.3 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-30661 | HIGH 7.3 | juniper junos An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processing of Juniper Networks Junos OS allows a local, low-privileged user to install scripts to be executed as root, leading to privilege escalation. A local user wit | 0.2% | — |
| CVE-2025-30001 | HIGH 7.3 | apache streampark Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. | 0.6% | — |
| CVE-2025-29826 | HIGH 7.3 | microsoft dataverse Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-29804 | HIGH 7.3 | microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 1.3% | — |
| CVE-2025-29803 | HIGH 7.3 | microsoft sql_server_management_studio Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2025-29802 | HIGH 7.3 | microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 0.9% | — |
| CVE-2025-29792 | HIGH 7.3 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 1.1% | — |
| CVE-2025-27821 | HIGH 7.3 | apache hadoop Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | 0.9% | — |
| CVE-2025-26631 | HIGH 7.3 | microsoft visual_studio_code Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-26628 | HIGH 7.3 | microsoft azure_local_cluster Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally. | 1.4% | — |