IT
58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.165 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-38257 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Prevent overflow in size calculation for memdup_user() Number of apqn target list entries contained in 'nr_apqns' variable is determined by userspace via an ioctl call so the resu 0.2%
CVE-2025-38239 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Fix invalid node index On a system with DRAM interleave enabled, out-of-bound access is detected: megaraid_sas 0000:3f:00.0: requested/available msix 128/128 poll_queue 0.2%
CVE-2025-38197 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell_rbu: Fix list usage Pass the correct list head to list_for_each_entry*() when looping through the packet list. Without this patch, reading the packet data via sysfs will 0.2%
CVE-2025-38004 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates The CAN broadcast manager (CAN BCM) can send a sequence of CAN frames via hrtimer. The content and also the length of the sequence can be cha 0.2%
CVE-2025-37931 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: btrfs: adjust subpage bit start based on sectorsize When running machines with 64k page size and a 16k nodesize we started seeing tree log corruption in production. This turned out to be be 0.2%
CVE-2025-35471 HIGH 7.3 conda-forge miniforge conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privile 0.2%
CVE-2025-33230 HIGH 7.3 nvidia cuda_toolkit NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a malicious string to the installation path. A successful exploit of this vulnerability might lead to escalation 1.4%
CVE-2025-33229 HIGH 7.3 nvidia cuda_toolkit NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitrary code with the same privileges as the NVIDIA Nsight Visual Studio Edition Monitor application. A successful exploit of this vulnerability 0.2%
CVE-2025-33042 HIGH 7.3 apache avro Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are r 0.6%
CVE-2025-32721 HIGH 7.3 microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-30661 HIGH 7.3 juniper junos An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processing of Juniper Networks Junos OS allows a local, low-privileged user to install scripts to be executed as root, leading to privilege escalation. A local user wit 0.2%
CVE-2025-30001 HIGH 7.3 apache streampark Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. 0.6%
CVE-2025-29826 HIGH 7.3 microsoft dataverse Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2025-29804 HIGH 7.3 microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. 1.3%
CVE-2025-29803 HIGH 7.3 microsoft sql_server_management_studio Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally. 0.8%
CVE-2025-29802 HIGH 7.3 microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. 0.9%
CVE-2025-29792 HIGH 7.3 microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. 1.1%
CVE-2025-27821 HIGH 7.3 apache hadoop Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. 0.9%
CVE-2025-26631 HIGH 7.3 microsoft visual_studio_code Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-26628 HIGH 7.3 microsoft azure_local_cluster Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally. 1.4%
CVE-2025-26497 HIGH 7.3 tableau tableau_server Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19. 0.3%
CVE-2025-25004 HIGH 7.3 microsoft powershell Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-25003 HIGH 7.3 microsoft visual_studio_2019 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-24998 HIGH 7.3 microsoft visual_studio_2017 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-24994 HIGH 7.3 microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. 1.2%