58.139 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.139 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-26628 | HIGH 7.3 | microsoft azure_local_cluster Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally. | 1.4% | — |
| CVE-2025-26497 | HIGH 7.3 | tableau tableau_server Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19. | 0.3% | — |
| CVE-2025-25004 | HIGH 7.3 | microsoft powershell Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-25003 | HIGH 7.3 | microsoft visual_studio_2019 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-24998 | HIGH 7.3 | microsoft visual_studio_2017 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-24994 | HIGH 7.3 | microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | 1.2% | — |
| CVE-2025-24076 | HIGH 7.3 | microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | 3.2% | — |
| CVE-2025-24042 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-24039 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2025-23242 | HIGH 7.3 | nvidia riva NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, or information disclosure. | 1.9% | — |
| CVE-2025-22094 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: powerpc/perf: Fix ref-counting on the PMU 'vpa_pmu' Commit 176cda0619b6 ("powerpc/perf: Add perf interface to expose vpa counters") introduced 'vpa_pmu' to expose Book3s-HV nested APIv2 prov | 0.2% | — |
| CVE-2025-22090 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Fix VM_PAT handling when fork() fails in copy_page_range() If track_pfn_copy() fails, we already added the dst VMA to the maple tree. As fork() fails, we'll cleanup the maple tre | 0.2% | — |
| CVE-2025-22019 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bcachefs: bch2_ioctl_subvolume_destroy() fixes bch2_evict_subvolume_inodes() was getting stuck - due to incorrectly pruning the dcache. Also, fix missing permissions checks. | 0.2% | — |
| CVE-2025-22013 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Unconditionally save+flush host FPSIMD/SVE/SME state There are several problems with the way hyp code lazily saves the host's FPSIMD/SVE state, including: * Host SVE being disca | 0.2% | — |
| CVE-2025-21959 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() Since commit b36e4523d4d5 ("netfilter: nf_conncount: fix garbage collection confirm race"), `cpu` and `ji | 0.4% | — |
| CVE-2025-21839 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop Move the conditional loading of hardware DR6 with the guest's DR6 value out of the core .vcpu_run() loop to fix a bu | 0.2% | — |
| CVE-2025-21830 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: landlock: Handle weird files A corrupted filesystem (e.g. bcachefs) might return weird files. Instead of throwing a warning and allowing access to such file, treat them as regular files. | 0.2% | — |
| CVE-2025-21789 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: LoongArch: csum: Fix OoB access in IP checksum code for negative lengths Commit 69e3a6aa6be2 ("LoongArch: Add checksum optimization for 64-bit system") would cause an undefined shift and an | 0.2% | — |
| CVE-2025-21682 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: always recalculate features after XDP clearing, fix null-deref Recalculate features when XDP is detached. Before: # ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp # ip li | 0.2% | — |
| CVE-2025-21647 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flow fairness counts Even though we fixed a logic error in the commit cited below, syzbot still managed to trigger an underflow of the per-hos | 0.3% | — |
| CVE-2025-21405 | HIGH 7.3 | microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2025-21331 | HIGH 7.3 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2025-21206 | HIGH 7.3 | microsoft visual_studio_2017 Visual Studio Installer Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-21173 | HIGH 7.3 | microsoft .net .NET Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2025-20210 | HIGH 7.3 | cisco catalyst_center A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This vulnerability is due to the lack of authentication | 0.4% | — |