58.165 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-49690 | HIGH 7.4 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-48004 | HIGH 7.4 | microsoft windows_11_22h2 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | 2.0% | — |
| CVE-2025-33088 | HIGH 7.4 | ibm concert IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to incorrect file permissions for critical resources. | 0.1% | — |
| CVE-2025-30648 | HIGH 7.4 | juniper junos An Improper Input Validation vulnerability in the Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause the jdhcpd process to crash resulting in a Denial of Service (DoS). When a s | 0.2% | — |
| CVE-2025-30384 | HIGH 7.4 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | 1.3% | — |
| CVE-2025-29838 | HIGH 7.4 | microsoft windows_11_24h2 Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-21591 | HIGH 7.4 | juniper junos A Buffer Access with Incorrect Length Value vulnerability in the jdhcpd daemon of Juniper Networks Junos OS, when DHCP snooping is enabled, allows an unauthenticated, adjacent, attacker to send a DHCP packet with a malformed DHCP option to cause jdhcp to crash | 0.3% | — |
| CVE-2025-21399 | HIGH 7.4 | microsoft edge_update Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-21183 | HIGH 7.4 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2025-21182 | HIGH 7.4 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2025-20311 | HIGH 7.4 | cisco ios_xe A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traffic. This vulnerabili | 0.2% | — |
| CVE-2025-20202 | HIGH 7.4 | cisco ios_xe A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of access point (AP | 0.2% | — |
| CVE-2025-20189 | HIGH 7.4 | cisco ios_xe A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) c | 0.2% | — |
| CVE-2025-20141 | HIGH 7.4 | cisco ios_xr A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco | 0.2% | — |
| CVE-2025-20140 | HIGH 7.4 | cisco ios_xe A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition. This vulnerability is due to | 0.2% | — |
| CVE-2025-11198 | HIGH 7.4 | juniper security_director_policy_enforcer A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allows an unauthenticated, network-based attacker to replace legitimate vSRX images with malicious ones. If a trusted user initiates deploymen | 0.3% | — |
| CVE-2024-53165 | HIGH 7.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sh: intc: Fix use-after-free bug in register_intc_controller() In the error handling for this function, d is freed without ever removing it from intc_list which would lead to a use after fre | 0.3% | — |
| CVE-2024-49070 | HIGH 7.4 | microsoft sharepoint_server Microsoft SharePoint Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2024-46817 | HIGH 7.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6 [Why] Coverity reports OVERRUN warning. Should abort amdgpu_dm initialize. [How] Return failure to amdgpu_dm_init. | 0.3% | — |
| CVE-2024-43610 | HIGH 7.4 | microsoft copilot_studio Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector | 1.1% | — |
| CVE-2024-43553 | HIGH 7.4 | microsoft windows_10_1507 NT OS Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-43550 | HIGH 7.4 | microsoft windows_10_1507 Windows Secure Channel Spoofing Vulnerability | 1.1% | — |
| CVE-2024-3383 | HIGH 7.4 | paloaltonetworks pan-os A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed | 0.6% | — |
| CVE-2024-33507 | HIGH 7.4 | fortinet fortiisolator An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauth | 0.4% | — |
| CVE-2024-32049 | HIGH 7.4 | f5 big-ip_next_central_manager BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.5% | — |