IT
58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.165 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-24076 HIGH 7.3 microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. 3.2%
CVE-2025-24042 HIGH 7.3 microsoft visual_studio_code Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability 0.7%
CVE-2025-24039 HIGH 7.3 microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability 0.8%
CVE-2025-23242 HIGH 7.3 nvidia riva NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, or information disclosure. 1.9%
CVE-2025-22094 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: powerpc/perf: Fix ref-counting on the PMU 'vpa_pmu' Commit 176cda0619b6 ("powerpc/perf: Add perf interface to expose vpa counters") introduced 'vpa_pmu' to expose Book3s-HV nested APIv2 prov 0.2%
CVE-2025-22090 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Fix VM_PAT handling when fork() fails in copy_page_range() If track_pfn_copy() fails, we already added the dst VMA to the maple tree. As fork() fails, we'll cleanup the maple tre 0.2%
CVE-2025-22019 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bcachefs: bch2_ioctl_subvolume_destroy() fixes bch2_evict_subvolume_inodes() was getting stuck - due to incorrectly pruning the dcache. Also, fix missing permissions checks. 0.2%
CVE-2025-22013 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Unconditionally save+flush host FPSIMD/SVE/SME state There are several problems with the way hyp code lazily saves the host's FPSIMD/SVE state, including: * Host SVE being disca 0.2%
CVE-2025-21959 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() Since commit b36e4523d4d5 ("netfilter: nf_conncount: fix garbage collection confirm race"), `cpu` and `ji 0.4%
CVE-2025-21839 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop Move the conditional loading of hardware DR6 with the guest's DR6 value out of the core .vcpu_run() loop to fix a bu 0.2%
CVE-2025-21830 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: landlock: Handle weird files A corrupted filesystem (e.g. bcachefs) might return weird files. Instead of throwing a warning and allowing access to such file, treat them as regular files. 0.2%
CVE-2025-21789 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: LoongArch: csum: Fix OoB access in IP checksum code for negative lengths Commit 69e3a6aa6be2 ("LoongArch: Add checksum optimization for 64-bit system") would cause an undefined shift and an 0.2%
CVE-2025-21682 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: always recalculate features after XDP clearing, fix null-deref Recalculate features when XDP is detached. Before: # ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp # ip li 0.2%
CVE-2025-21647 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flow fairness counts Even though we fixed a logic error in the commit cited below, syzbot still managed to trigger an underflow of the per-hos 0.3%
CVE-2025-21405 HIGH 7.3 microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability 0.5%
CVE-2025-21331 HIGH 7.3 microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability 1.0%
CVE-2025-21206 HIGH 7.3 microsoft visual_studio_2017 Visual Studio Installer Elevation of Privilege Vulnerability 0.7%
CVE-2025-21173 HIGH 7.3 microsoft .net .NET Elevation of Privilege Vulnerability 1.2%
CVE-2025-20210 HIGH 7.3 cisco catalyst_center A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This vulnerability is due to the lack of authentication 0.4%
CVE-2025-11792 HIGH 7.3 acronis agent Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 41124. 0.1%
CVE-2024-9842 HIGH 7.3 ivanti secure_access_client Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders. 0.2%
CVE-2024-8996 HIGH 7.3 grafana agent Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Agent Flow: before 0.43.2 0.3%
CVE-2024-8975 HIGH 7.3 grafana alloy Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1. 0.3%
CVE-2024-7890 HIGH 7.3 citrix workspace Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows 0.2%
CVE-2024-7889 HIGH 7.3 citrix workspace Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows 0.2%