58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-25002 | MED 6.8 | microsoft azure_local_cluster Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network. | 1.1% | — |
| CVE-2025-24890 | MED 6.8 | gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered elevated token. In gix-s | 0.2% | — |
| CVE-2025-22219 | MED 6.8 | vmware aria_operations_for_logs VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations | 0.7% | — |
| CVE-2025-21349 | MED 6.8 | microsoft windows_10_1507 Windows Remote Desktop Configuration Service Tampering Vulnerability | 1.1% | — |
| CVE-2025-21211 | MED 6.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2025-20181 | MED 6.8 | cisco ios A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with physical access to the device to execute persist | 0.2% | — |
| CVE-2025-14728 | MED 6.8 | rapid7 velociraptor Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write in the datastore direct | 0.6% | — |
| CVE-2025-12763 | MED 6.8 | pgadmin pgadmin_4 pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing speciall | 0.9% | — |
| CVE-2024-49782 | MED 6.8 | ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit this vulnerability to gain access to sensitive information disclosed through email notifications genera | 0.4% | — |
| CVE-2024-49110 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-49092 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-49083 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-49082 | MED 6.8 | microsoft windows_10_1507 Windows File Explorer Information Disclosure Vulnerability | 1.5% | — |
| CVE-2024-49078 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-49077 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-49073 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-48893 | MED 6.8 | fortinet fortisoar An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious | 0.5% | — |
| CVE-2024-48892 | MED 6.8 | fortinet fortisoar A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack. | 0.4% | — |
| CVE-2024-47139 | MED 6.8 | f5 big-iq_centralized_management A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user. Note: Software versio | 0.6% | — |
| CVE-2024-43643 | MED 6.8 | microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-43638 | MED 6.8 | microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-43637 | MED 6.8 | microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-43634 | MED 6.8 | microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-43543 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2024-43536 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.6% | — |