IT
58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.414 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-25002 MED 6.8 microsoft azure_local_cluster Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network. 1.1% —
CVE-2025-24890 MED 6.8 gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered elevated token. In gix-s 0.2% —
CVE-2025-22219 MED 6.8 vmware aria_operations_for_logs VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations 0.7% —
CVE-2025-21349 MED 6.8 microsoft windows_10_1507 Windows Remote Desktop Configuration Service Tampering Vulnerability 1.1% —
CVE-2025-21211 MED 6.8 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.8% —
CVE-2025-20181 MED 6.8 cisco ios A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with physical access to the device to execute persist 0.2% —
CVE-2025-14728 MED 6.8 rapid7 velociraptor Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write in the datastore direct 0.6% —
CVE-2025-12763 MED 6.8 pgadmin pgadmin_4 pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing speciall 0.9% —
CVE-2024-49782 MED 6.8 ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0  could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit this vulnerability to gain access to sensitive information disclosed through email notifications genera 0.4% —
CVE-2024-49110 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability 0.9% —
CVE-2024-49092 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability 0.8% —
CVE-2024-49083 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability 0.8% —
CVE-2024-49082 MED 6.8 microsoft windows_10_1507 Windows File Explorer Information Disclosure Vulnerability 1.5% —
CVE-2024-49078 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability 0.9% —
CVE-2024-49077 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability 0.9% —
CVE-2024-49073 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability 0.9% —
CVE-2024-48893 MED 6.8 fortinet fortisoar An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious 0.5% —
CVE-2024-48892 MED 6.8 fortinet fortisoar A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack. 0.4% —
CVE-2024-47139 MED 6.8 f5 big-iq_centralized_management A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user.   Note: Software versio 0.6% —
CVE-2024-43643 MED 6.8 microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability 0.7% —
CVE-2024-43638 MED 6.8 microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability 0.7% —
CVE-2024-43637 MED 6.8 microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability 0.7% —
CVE-2024-43634 MED 6.8 microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability 0.7% —
CVE-2024-43543 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability 0.6% —
CVE-2024-43536 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability 0.6% —