58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-38257 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Prevent overflow in size calculation for memdup_user() Number of apqn target list entries contained in 'nr_apqns' variable is determined by userspace via an ioctl call so the resu | 0.2% | — |
| CVE-2025-38239 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Fix invalid node index On a system with DRAM interleave enabled, out-of-bound access is detected: megaraid_sas 0000:3f:00.0: requested/available msix 128/128 poll_queue | 0.2% | — |
| CVE-2025-38197 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell_rbu: Fix list usage Pass the correct list head to list_for_each_entry*() when looping through the packet list. Without this patch, reading the packet data via sysfs will | 0.2% | — |
| CVE-2025-38004 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates The CAN broadcast manager (CAN BCM) can send a sequence of CAN frames via hrtimer. The content and also the length of the sequence can be cha | 0.2% | — |
| CVE-2025-37931 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: btrfs: adjust subpage bit start based on sectorsize When running machines with 64k page size and a 16k nodesize we started seeing tree log corruption in production. This turned out to be be | 0.2% | — |
| CVE-2025-35471 | HIGH 7.3 | conda-forge miniforge conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privile | 0.2% | — |
| CVE-2025-33230 | HIGH 7.3 | nvidia cuda_toolkit NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a malicious string to the installation path. A successful exploit of this vulnerability might lead to escalation | 1.4% | — |
| CVE-2025-33229 | HIGH 7.3 | nvidia cuda_toolkit NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitrary code with the same privileges as the NVIDIA Nsight Visual Studio Edition Monitor application. A successful exploit of this vulnerability | 0.2% | — |
| CVE-2025-33042 | HIGH 7.3 | apache avro Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are r | 0.6% | — |
| CVE-2025-32721 | HIGH 7.3 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-30661 | HIGH 7.3 | juniper junos An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processing of Juniper Networks Junos OS allows a local, low-privileged user to install scripts to be executed as root, leading to privilege escalation. A local user wit | 0.2% | — |
| CVE-2025-30001 | HIGH 7.3 | apache streampark Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. | 0.6% | — |
| CVE-2025-29826 | HIGH 7.3 | microsoft dataverse Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-29804 | HIGH 7.3 | microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 1.3% | — |
| CVE-2025-29803 | HIGH 7.3 | microsoft sql_server_management_studio Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2025-29802 | HIGH 7.3 | microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 0.9% | — |
| CVE-2025-29792 | HIGH 7.3 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 1.1% | — |
| CVE-2025-27821 | HIGH 7.3 | apache hadoop Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | 0.9% | — |
| CVE-2025-26631 | HIGH 7.3 | microsoft visual_studio_code Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-26628 | HIGH 7.3 | microsoft azure_local_cluster Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally. | 1.4% | — |
| CVE-2025-26497 | HIGH 7.3 | tableau tableau_server Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19. | 0.3% | — |
| CVE-2025-25004 | HIGH 7.3 | microsoft powershell Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-25003 | HIGH 7.3 | microsoft visual_studio_2019 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-24998 | HIGH 7.3 | microsoft visual_studio_2017 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-24994 | HIGH 7.3 | microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | 1.2% | — |