58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-24076 | HIGH 7.3 | microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | 3.2% | — |
| CVE-2025-24042 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-24039 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2025-23242 | HIGH 7.3 | nvidia riva NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, or information disclosure. | 1.9% | — |
| CVE-2025-22094 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: powerpc/perf: Fix ref-counting on the PMU 'vpa_pmu' Commit 176cda0619b6 ("powerpc/perf: Add perf interface to expose vpa counters") introduced 'vpa_pmu' to expose Book3s-HV nested APIv2 prov | 0.2% | — |
| CVE-2025-22090 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Fix VM_PAT handling when fork() fails in copy_page_range() If track_pfn_copy() fails, we already added the dst VMA to the maple tree. As fork() fails, we'll cleanup the maple tre | 0.2% | — |
| CVE-2025-22019 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bcachefs: bch2_ioctl_subvolume_destroy() fixes bch2_evict_subvolume_inodes() was getting stuck - due to incorrectly pruning the dcache. Also, fix missing permissions checks. | 0.2% | — |
| CVE-2025-22013 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Unconditionally save+flush host FPSIMD/SVE/SME state There are several problems with the way hyp code lazily saves the host's FPSIMD/SVE state, including: * Host SVE being disca | 0.2% | — |
| CVE-2025-21959 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() Since commit b36e4523d4d5 ("netfilter: nf_conncount: fix garbage collection confirm race"), `cpu` and `ji | 0.4% | — |
| CVE-2025-21839 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop Move the conditional loading of hardware DR6 with the guest's DR6 value out of the core .vcpu_run() loop to fix a bu | 0.2% | — |
| CVE-2025-21830 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: landlock: Handle weird files A corrupted filesystem (e.g. bcachefs) might return weird files. Instead of throwing a warning and allowing access to such file, treat them as regular files. | 0.2% | — |
| CVE-2025-21789 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: LoongArch: csum: Fix OoB access in IP checksum code for negative lengths Commit 69e3a6aa6be2 ("LoongArch: Add checksum optimization for 64-bit system") would cause an undefined shift and an | 0.2% | — |
| CVE-2025-21682 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: always recalculate features after XDP clearing, fix null-deref Recalculate features when XDP is detached. Before: # ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp # ip li | 0.2% | — |
| CVE-2025-21647 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flow fairness counts Even though we fixed a logic error in the commit cited below, syzbot still managed to trigger an underflow of the per-hos | 0.3% | — |
| CVE-2025-21405 | HIGH 7.3 | microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2025-21331 | HIGH 7.3 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2025-21206 | HIGH 7.3 | microsoft visual_studio_2017 Visual Studio Installer Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-21173 | HIGH 7.3 | microsoft .net .NET Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2025-20210 | HIGH 7.3 | cisco catalyst_center A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This vulnerability is due to the lack of authentication | 0.4% | — |
| CVE-2025-11792 | HIGH 7.3 | acronis agent Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 41124. | 0.1% | — |
| CVE-2024-9842 | HIGH 7.3 | ivanti secure_access_client Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders. | 0.2% | — |
| CVE-2024-8996 | HIGH 7.3 | grafana agent Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Agent Flow: before 0.43.2 | 0.3% | — |
| CVE-2024-8975 | HIGH 7.3 | grafana alloy Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1. | 0.3% | — |
| CVE-2024-7890 | HIGH 7.3 | citrix workspace Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | 0.2% | — |
| CVE-2024-7889 | HIGH 7.3 | citrix workspace Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | 0.2% | — |