56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.959 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-58325 | HIGH 8.2 | fortinet fortios An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system commands via crafted CLI co | 0.3% | — |
| CVE-2025-53787 | HIGH 8.2 | microsoft 365_copilot_chat Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | 0.7% | — |
| CVE-2025-52454 | HIGH 8.2 | tableau tableau_server Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19. | 0.3% | — |
| CVE-2025-52453 | HIGH 8.2 | tableau tableau_server Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19. | 0.3% | — |
| CVE-2025-47977 | HIGH 8.2 | microsoft nuance_digital_engagement_platform Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2025-38571 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix client side handling of tls alerts A security exploit was discovered in NFS over TLS in tls_alert_recv due to its assumption that there is valid data in the msghdr's iterator's k | 0.3% | — |
| CVE-2025-38491 | HIGH 8.2 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: mptcp: make fallback action and fallback decision atomic Syzkaller reported the following splat: WARNING: CPU: 1 PID: 7704 at net/mptcp/protocol.h:1223 __mptcp_do_fallback net/mptcp/proto | 0.2% | — |
| CVE-2025-37749 | HIGH 8.2 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: ppp: Add bound checking for skb data on ppp_sync_txmung Ensure we have enough data in linear buffer from skb before accessing initial bytes. This prevents potential out-of-bounds access | 0.4% | — |
| CVE-2025-24989 | HIGH 8.2 | microsoft power_pages An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected cust | 1.6% | |
| CVE-2025-22249 | HIGH 8.2 | vmware aria_automation VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious craf | 0.3% | — |
| CVE-2025-22225 | HIGH 8.2 | ransomware vmware cloud_foundation VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. | 1.0% | |
| CVE-2025-21890 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: idpf: fix checksums set in idpf_rx_rsc() idpf_rx_rsc() uses skb_transport_offset(skb) while the transport header is not set yet. This triggers the following warning for CONFIG_DEBUG_NET=y b | 0.4% | — |
| CVE-2025-21710 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: correct handling of extreme memory squeeze Testing with iperf3 using the "pasta" protocol splicer has revealed a problem in the way tcp handles window advertising in extreme memory sque | 0.3% | — |
| CVE-2025-21629 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets The blamed commit disabled hardware offoad of IPv6 packets with extension headers on devices that advertise NETIF_F_IPV6_CSUM, bas | 0.4% | — |
| CVE-2025-21396 | HIGH 8.2 | microsoft account Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-58239 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us non-DATA If we have a non-DATA record on the rx_list and another record of the same type still on the queue, we will end up merging them: | 0.3% | — |
| CVE-2024-54027 | HIGH 8.2 | fortinet fortisandbox A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, version 3.1.5 and below, version 3.0.7 to 3.0.5 may allow a privileged attacker wi | 0.2% | — |
| CVE-2024-50299 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sctp: properly validate chunk size in sctp_sf_ootb() A size validation fix similar to that in Commit 50619dbf8db7 ("sctp: add size validation when walking chunks") is also required in sctp_s | 0.6% | — |
| CVE-2024-50185 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: handle consistently DSS corruption Bugged peer implementation can send corrupted DSS options, consistently hitting a few warning in the data path. Use DEBUG_NET assertions, to avoid t | 0.6% | — |
| CVE-2024-49068 | HIGH 8.2 | microsoft sharepoint_server Microsoft SharePoint Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2024-49052 | HIGH 8.2 | microsoft azure_functions Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-47604 | HIGH 8.2 | microsoft nugetgallery NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser. | 0.7% | — |
| CVE-2024-47490 | HIGH 8.2 | juniper junos_os_evolved An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network based attacker to cause increased consumption | 0.6% | — |
| CVE-2024-45720 | HIGH 8.2 | apache subversion On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other progra | 0.6% | — |
| CVE-2024-45009 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only decrement add_addr_accepted for MPJ req Adding the following warning ... WARN_ON_ONCE(msk->pm.add_addr_accepted == 0) ... before decrementing the add_addr_accepted counte | 0.5% | — |