58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-55335 | HIGH 7.4 | microsoft windows_10_1507 Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55077 | HIGH 7.4 | tylertech erp_pro_9 Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating system commands within the remote Microsoft Windows environment with the privileges of the authenticated user. Tyler Technologies deployed ha | 0.2% | — |
| CVE-2025-54809 | HIGH 7.4 | f5 f5_access F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.3% | — |
| CVE-2025-54103 | HIGH 7.4 | microsoft windows_10_21h2 Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-49812 | HIGH 7.4 | apache http_server In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upg | 0.6% | — |
| CVE-2025-49741 | HIGH 7.4 | microsoft edge_chromium No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 3.6% | — |
| CVE-2025-49690 | HIGH 7.4 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-48004 | HIGH 7.4 | microsoft windows_11_22h2 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | 2.0% | — |
| CVE-2025-33088 | HIGH 7.4 | ibm concert IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to incorrect file permissions for critical resources. | 0.1% | — |
| CVE-2025-30648 | HIGH 7.4 | juniper junos An Improper Input Validation vulnerability in the Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause the jdhcpd process to crash resulting in a Denial of Service (DoS). When a s | 0.2% | — |
| CVE-2025-30384 | HIGH 7.4 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | 1.3% | — |
| CVE-2025-29838 | HIGH 7.4 | microsoft windows_11_24h2 Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-21591 | HIGH 7.4 | juniper junos A Buffer Access with Incorrect Length Value vulnerability in the jdhcpd daemon of Juniper Networks Junos OS, when DHCP snooping is enabled, allows an unauthenticated, adjacent, attacker to send a DHCP packet with a malformed DHCP option to cause jdhcp to crash | 0.3% | — |
| CVE-2025-21399 | HIGH 7.4 | microsoft edge_update Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-21183 | HIGH 7.4 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2025-21182 | HIGH 7.4 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2025-20311 | HIGH 7.4 | cisco ios_xe A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traffic. This vulnerabili | 0.2% | — |
| CVE-2025-20202 | HIGH 7.4 | cisco ios_xe A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of access point (AP | 0.2% | — |
| CVE-2025-20189 | HIGH 7.4 | cisco ios_xe A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) c | 0.2% | — |
| CVE-2025-20141 | HIGH 7.4 | cisco ios_xr A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco | 0.2% | — |
| CVE-2025-20140 | HIGH 7.4 | cisco ios_xe A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition. This vulnerability is due to | 0.2% | — |
| CVE-2025-11198 | HIGH 7.4 | juniper security_director_policy_enforcer A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allows an unauthenticated, network-based attacker to replace legitimate vSRX images with malicious ones. If a trusted user initiates deploymen | 0.3% | — |
| CVE-2024-53165 | HIGH 7.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sh: intc: Fix use-after-free bug in register_intc_controller() In the error handling for this function, d is freed without ever removing it from intc_list which would lead to a use after fre | 0.3% | — |
| CVE-2024-49070 | HIGH 7.4 | microsoft sharepoint_server Microsoft SharePoint Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2024-46817 | HIGH 7.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6 [Why] Coverity reports OVERRUN warning. Should abort amdgpu_dm initialize. [How] Return failure to amdgpu_dm_init. | 0.3% | — |