IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.793 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-69274 HIGH 8.8 broadcom dx_netops_spectrum Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issue affects DX NetOps Spectrum: 24.3.10 and earlier. 0.2%
CVE-2025-69219 HIGH 8.8 apache airflow_providers_http A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since direct DB access is not usual and recommended for Airflow, the likel 0.7%
CVE-2025-6724 HIGH 8.8 chef automate In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL command. 0.3%
CVE-2025-66524 HIGH 8.8 apache nifi Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state information. The GetAsanaObject Processor used generic Java Object serial 0.5%
CVE-2025-66518 HIGH 8.8 apache kyuubi Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10 1.0%
CVE-2025-65115 HIGH 8.8 hitachi job_management_partner_1\/it_desktop_management-manager Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on 0.6%
CVE-2025-64678 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2025-64672 HIGH 8.8 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 1.0%
CVE-2025-64655 HIGH 8.8 microsoft dynamics_omnichannel_sdk_storage_containers Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2025-62550 HIGH 8.8 microsoft azure_monitor_agent Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. 0.7%
CVE-2025-62549 HIGH 8.8 microsoft windows_10_1607 Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 1.3%
CVE-2025-62456 HIGH 8.8 microsoft windows_11_23h2 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. 1.1%
CVE-2025-62228 HIGH 8.8 apache flink_cdc Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-in database user can trigger the attack, we recommend users update Flink CDC vers 0.4%
CVE-2025-62222 HIGH 8.8 microsoft github_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2025-62220 HIGH 8.8 microsoft windows_subsystem_for_linux Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2025-61955 HIGH 8.8 f5 f5os-a A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escalate their privileges.  A successful exploit may allow the attacker to cross a security boundary.  Note: Software versions which have reached 0.2%
CVE-2025-60024 HIGH 8.8 fortinet fortivoice Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 may allow a privileged authenticated attacker to write ar 0.4%
CVE-2025-59499 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 1.1%
CVE-2025-59295 HIGH 8.8 microsoft windows_10_1507 Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. 1.8%
CVE-2025-59249 HIGH 8.8 microsoft exchange_server Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2025-59247 HIGH 8.8 microsoft azure_playfab Azure PlayFab Elevation of Privilege Vulnerability 1.4%
CVE-2025-59237 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 2.3%
CVE-2025-59228 HIGH 8.8 microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.3%
CVE-2025-59213 HIGH 8.8 microsoft configuration_manager_2403 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network. 0.3%
CVE-2025-58718 HIGH 8.8 microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.6%