58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-33051 | HIGH 7.5 | microsoft exchange_server Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2025-33050 | HIGH 7.5 | microsoft windows_server_2016 Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.8% | — |
| CVE-2025-32725 | HIGH 7.5 | microsoft windows_server_2016 Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.8% | — |
| CVE-2025-32724 | HIGH 7.5 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | 1.8% | — |
| CVE-2025-3221 | HIGH 7.5 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. | 0.4% | — |
| CVE-2025-31698 | HIGH 7.5 | apache traffic_server ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to | 0.6% | — |
| CVE-2025-31650 | HIGH 7.5 | apache tomcat Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfM | 59.9% | — |
| CVE-2025-30660 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).When processing a high ra | 0.4% | — |
| CVE-2025-30659 | HIGH 7.5 | juniper junos An Improper Handling of Length Parameter Inconsistency vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a device configure | 0.4% | — |
| CVE-2025-30658 | HIGH 7.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the Anti-Virus processing of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX platforms with Anti-V | 0.4% | — |
| CVE-2025-30656 | HIGH 7.5 | juniper junos An Improper Handling of Additional Special Element vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series with MS-MPC, MS-MIC and SPC3, and SRX Series, allows an unauthenticated, network-based attacker to cause a Denial-o | 0.4% | — |
| CVE-2025-30651 | HIGH 7.5 | juniper junos A Buffer Access with Incorrect Length Value vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When an attacker sends a spec | 0.4% | — |
| CVE-2025-30649 | HIGH 7.5 | juniper junos An Improper Input Validation vulnerability in the syslog stream TCP transport of Juniper Networks Junos OS on MX240, MX480 and MX960 devices with MX-SPC3 Security Services Card allows an unauthenticated, network-based attacker, to send specific spoofed packets | 0.4% | — |
| CVE-2025-30645 | HIGH 7.5 | juniper junos A NULL Pointer Dereference vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker causing specific, valid control traffic to be sent out of a Dual-Stack (DS) Lite tunnel to crash the flowd process, resulting in a | 0.4% | — |
| CVE-2025-30644 | HIGH 7.5 | juniper junos A Heap-based Buffer Overflow vulnerability in the flexible PIC concentrator (FPC) of Juniper Networks Junos OS on EX2300, EX3400, EX4100, EX4300, EX4300MP, EX4400, EX4600, EX4650-48Y, and QFX5k Series allows an attacker to send a specific DHCP packet to the de | 0.3% | — |
| CVE-2025-30399 | HIGH 7.5 | microsoft .net Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. | 1.1% | — |
| CVE-2025-30397 | HIGH 7.5 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. | 26.8% | |
| CVE-2025-29971 | HIGH 7.5 | microsoft windows_11_22h2 Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network. | 64.4% | — |
| CVE-2025-29969 | HIGH 7.5 | microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network. | 1.2% | — |
| CVE-2025-29847 | HIGH 7.5 | apache linkis A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if the URL parameter configured on the frontend has undergone multiple rounds of URL encoding, it may bypass the | 0.9% | — |
| CVE-2025-29842 | HIGH 7.5 | microsoft windows_10_1507 Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network. | 0.4% | — |
| CVE-2025-29834 | HIGH 7.5 | microsoft edge_chromium Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-29831 | HIGH 7.5 | microsoft windows_server_2008 Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-29816 | HIGH 7.5 | microsoft 365_apps Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network. | 0.5% | — |
| CVE-2025-29810 | HIGH 7.5 | microsoft windows_10_1507 Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. | 2.5% | — |