58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-53805 | HIGH 7.5 | microsoft windows_11_22h2 Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network. | 1.4% | — |
| CVE-2025-53793 | HIGH 7.5 | microsoft azure_stack_hub Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2025-53783 | HIGH 7.5 | microsoft dynamics_365_guides Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-53722 | HIGH 7.5 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network. | 21.1% | — |
| CVE-2025-53506 | HIGH 7.5 | apache tomcat Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10 | 2.0% | — |
| CVE-2025-53477 | HIGH 7.5 | apache nimble NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference. This issue requires disabled asserts and broken or bogus Bluetooth controller and thus seve | 0.8% | — |
| CVE-2025-53474 | HIGH 7.5 | f5 big-ip_access_policy_manager When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.3% | — |
| CVE-2025-53379 | HIGH 7.5 | fortinet fortiauthenticator A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. | 0.5% | — |
| CVE-2025-53020 | HIGH 7.5 | apache http_server Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue. | 4.8% | — |
| CVE-2025-52981 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX1600, SRX2300, SRX 4000 Series, and SRX5000 Series with SPC3 allows an unauthenticated, network-based att | 0.4% | — |
| CVE-2025-52980 | HIGH 7.5 | juniper junos A Use of Incorrect Byte Ordering vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS on SRX300 Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a BGP update is received over an | 0.5% | — |
| CVE-2025-52946 | HIGH 7.5 | juniper junos A Use After Free vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an attacker sending a BGP update with a specifically malformed AS PATH to cause rpd to crash, resulting in a Denial of | 0.4% | — |
| CVE-2025-52585 | HIGH 7.5 | f5 big-ip_access_policy_manager When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software | 0.3% | — |
| CVE-2025-52520 | HIGH 7.5 | apache tomcat For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9. | 2.1% | — |
| CVE-2025-52435 | HIGH 7.5 | apache nimble J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to | 0.2% | — |
| CVE-2025-52434 | HIGH 7.5 | apache tomcat Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue aff | 1.9% | — |
| CVE-2025-50169 | HIGH 7.5 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-49763 | HIGH 7.5 | apache traffic_server ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting for the plugin (--max-inclusion-depth) to limit it. This issue affects Apache Traf | 0.7% | — |
| CVE-2025-49719 | HIGH 7.5 | microsoft sql_server_2016 Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network. | 10.8% | — |
| CVE-2025-49718 | HIGH 7.5 | microsoft sql_server_2019 Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network. | 3.3% | — |
| CVE-2025-49716 | HIGH 7.5 | microsoft windows_server_2008 Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network. | 1.4% | — |
| CVE-2025-49715 | HIGH 7.5 | microsoft dynamics_365 Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2025-49656 | HIGH 7.5 | apache jena Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue. | 1.5% | — |
| CVE-2025-49630 | HIGH 7.5 | apache http_server In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured f | 1.2% | — |
| CVE-2025-49506 | HIGH 7.5 | apache apr-util APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as | 0.4% | — |