56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.793 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-69274 | HIGH 8.8 | broadcom dx_netops_spectrum Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issue affects DX NetOps Spectrum: 24.3.10 and earlier. | 0.2% | — |
| CVE-2025-69219 | HIGH 8.8 | apache airflow_providers_http A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since direct DB access is not usual and recommended for Airflow, the likel | 0.7% | — |
| CVE-2025-6724 | HIGH 8.8 | chef automate In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL command. | 0.3% | — |
| CVE-2025-66524 | HIGH 8.8 | apache nifi Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state information. The GetAsanaObject Processor used generic Java Object serial | 0.5% | — |
| CVE-2025-66518 | HIGH 8.8 | apache kyuubi Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10 | 1.0% | — |
| CVE-2025-65115 | HIGH 8.8 | hitachi job_management_partner_1\/it_desktop_management-manager Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on | 0.6% | — |
| CVE-2025-64678 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-64672 | HIGH 8.8 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 1.0% | — |
| CVE-2025-64655 | HIGH 8.8 | microsoft dynamics_omnichannel_sdk_storage_containers Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2025-62550 | HIGH 8.8 | microsoft azure_monitor_agent Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-62549 | HIGH 8.8 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2025-62456 | HIGH 8.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2025-62228 | HIGH 8.8 | apache flink_cdc Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-in database user can trigger the attack, we recommend users update Flink CDC vers | 0.4% | — |
| CVE-2025-62222 | HIGH 8.8 | microsoft github_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-62220 | HIGH 8.8 | microsoft windows_subsystem_for_linux Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-61955 | HIGH 8.8 | f5 f5os-a A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. Note: Software versions which have reached | 0.2% | — |
| CVE-2025-60024 | HIGH 8.8 | fortinet fortivoice Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 may allow a privileged authenticated attacker to write ar | 0.4% | — |
| CVE-2025-59499 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2025-59295 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. | 1.8% | — |
| CVE-2025-59249 | HIGH 8.8 | microsoft exchange_server Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-59247 | HIGH 8.8 | microsoft azure_playfab Azure PlayFab Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2025-59237 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.3% | — |
| CVE-2025-59228 | HIGH 8.8 | microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.3% | — |
| CVE-2025-59213 | HIGH 8.8 | microsoft configuration_manager_2403 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network. | 0.3% | — |
| CVE-2025-58718 | HIGH 8.8 | microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.6% | — |