IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.793 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-49668 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-49663 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-49657 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2025-49215 HIGH 8.8 trendmicro trend_micro_endpoint_encryption A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on t 0.3%
CVE-2025-49214 HIGH 8.8 trendmicro trend_micro_endpoint_encryption An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged c 0.8%
CVE-2025-48824 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2025-48817 HIGH 8.8 microsoft remote_desktop_client Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2025-48734 HIGH 8.8 apache commons_beanutils Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However th 1.7%
CVE-2025-48208 HIGH 8.8 apache hertzbeat Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have an authenticated account with access, and the attack can only be triggered by crafting custom comman 0.6%
CVE-2025-47998 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2025-47986 HIGH 8.8 microsoft windows_10_1507 Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-47954 HIGH 8.8 microsoft sql_server_2022 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 1.5%
CVE-2025-47849 HIGH 8.8 apache cloudstack A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can get the API key and secret key of user-accounts of Admin role type in the same domain. This operation 0.5%
CVE-2025-47713 HIGH 8.8 apache cloudstack A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can reset the password of user-accounts of Admin role type. This operation is not appropriately restricte 0.5%
CVE-2025-47410 HIGH 8.8 apache geode Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on be 0.3%
CVE-2025-47181 HIGH 8.8 microsoft edge_update Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-47172 HIGH 8.8 microsoft sharepoint_enterprise_server Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.6%
CVE-2025-47166 HIGH 8.8 microsoft sharepoint_enterprise_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 15.2%
CVE-2025-47163 HIGH 8.8 microsoft sharepoint_enterprise_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 14.7%
CVE-2025-46265 HIGH 8.8 f5 f5os-a On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher privilege F5OS roles. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.4%
CVE-2025-4613 HIGH 8.8 google web_designer Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking users into downloading a malicious ad template 0.6%
CVE-2025-44016 HIGH 8.8 teamviewer digital_employee_experience A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file integrity validation via a crafted request. By providing a valid hash for a mali 0.3%
CVE-2025-4232 HIGH 8.8 paloaltonetworks globalprotect An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to escalate their privileges to root. 0.4%
CVE-2025-40039 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix race condition in RPC handle list access The 'sess->rpc_handle_list' XArray manages RPC handles within a ksmbd session. Access to this list is intended to be protected by 'sess->r 0.3%
CVE-2025-39961 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iommu/amd/pgtbl: Fix possible race while increase page table level The AMD IOMMU host page table implementation supports dynamic page table levels (up to 6 levels), starting with a 3-level c 0.1%