IT
58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.165 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-55240 HIGH 7.3 microsoft visual_studio_2017 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-55236 HIGH 7.3 microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally. 0.4%
CVE-2025-54911 HIGH 7.3 microsoft windows_10_1507 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-54116 HIGH 7.3 microsoft windows_10_1507 Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-50161 HIGH 7.3 microsoft windows_10_1507 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-50159 HIGH 7.3 microsoft windows_10_1507 Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-49682 HIGH 7.3 microsoft windows_10_21h2 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-49680 HIGH 7.3 microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally. 0.5%
CVE-2025-48500 HIGH 7.3 f5 big-ip_access_policy_manager A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer.  Note: Software versions which ha 0.1%
CVE-2025-46701 HIGH 7.3 apache tomcat Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0 2.9%
CVE-2025-41231 HIGH 7.3 vmware cloud_foundation VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information. 0.2%
CVE-2025-39960 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: gpiolib: acpi: initialize acpi_gpio_info struct Since commit 7c010d463372 ("gpiolib: acpi: Make sure we fill struct acpi_gpio_info"), uninitialized acpi_gpio_info struct are passed to __acpi 0.2%
CVE-2025-39798 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: NFS: Fix the setting of capabilities when automounting a new filesystem Capabilities cannot be inherited when we cross into a new filesystem. They need to be reset to the minimal defaults, a 0.3%
CVE-2025-39789 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: x86/aegis - Add missing error checks The skcipher_walk functions can allocate memory and can fail, so checking for errors is necessary. 0.1%
CVE-2025-39738 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: btrfs: do not allow relocation of partially dropped subvolumes [BUG] There is an internal report that balance triggered transaction abort, with the following call trace: item 85 key (5945 0.2%
CVE-2025-39694 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: s390/sclp: Fix SCCB present check Tracing code called by the SCLP interrupt handler contains early exits if the SCCB address associated with an interrupt is NULL. This check is performed aft 0.2%
CVE-2025-38687 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: comedi: fix race between polling and detaching syzbot reports a use-after-free in comedi in the below link, which is due to comedi gladly removing the allocated async area even though poll r 0.1%
CVE-2025-38679 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: media: venus: Fix OOB read due to missing payload bound check Currently, The event_seq_changed() handler processes a variable number of properties sent by the firmware. The number of propert 0.2%
CVE-2025-38657 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: mcc: prevent shift wrapping in rtw89_core_mlsr_switch() The "link_id" value comes from the user via debugfs. If it's larger than BITS_PER_LONG then that would result in shift w 0.1%
CVE-2025-38652 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in devs.path - touch /mnt/f2fs/012345678901234567890123456789012345678901234567890123 - truncate -s $((1024*1024*1024)) \ /mnt/f2fs/01234567890123 0.2%
CVE-2025-38573 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: spi: cs42l43: Property entry should be a null-terminated array The software node does not specify a count of property entries, so the array must be null-terminated. When unterminated, this 0.2%
CVE-2025-38547 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iio: adc: axp20x_adc: Add missing sentinel to AXP717 ADC channel maps The AXP717 ADC channel maps is missing a sentinel entry at the end. This causes a KASAN warning. Add the missing sentin 0.1%
CVE-2025-38508 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: x86/sev: Use TSC_FACTOR for Secure TSC frequency calculation When using Secure TSC, the GUEST_TSC_FREQ MSR reports a frequency based on the nominal P0 frequency, which deviates slightly (typ 0.1%
CVE-2025-38446 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: clk: imx: Fix an out-of-bounds access in dispmix_csr_clk_dev_data When num_parents is 4, __clk_register() occurs an out-of-bounds when accessing parent_names member. Use ARRAY_SIZE() instead 0.2%
CVE-2025-38314 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio-pci: Fix result size returned for the admin command completion The result size returned by virtio_pci_admin_dev_parts_get() is 8 bytes larger than the actual result data size. This oc 0.1%