56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-64403 | HIGH 8.1 | apache openoffice Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause such links to be loaded without pr | 1.2% | — |
| CVE-2025-62235 | HIGH 8.1 | apache nimble Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bond and re-bond with impostor. This issue affects Apache NimBLE: through 1.8.0. Users are recommended to upgrade | 0.4% | — |
| CVE-2025-61787 | HIGH 8.1 | deno deno Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a b | 2.1% | — |
| CVE-2025-59250 | HIGH 8.1 | microsoft jdbc_driver_for_sql_server Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2025-58137 | HIGH 8.1 | apache fineract Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encouraged to upgrade to version 1.13.0, the latest release. | 0.4% | — |
| CVE-2025-54820 | HIGH 8.1 | fortinet fortimanager A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via | 0.9% | — |
| CVE-2025-54550 | HIGH 8.1 | apache airflow The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be exploited to allow UI user who had access to modify XComs to perform arbitrary execution of code on the worker. S | 0.6% | — |
| CVE-2025-52970 | HIGH 8.1 | fortinet fortiweb A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and tar | 9.8% | — |
| CVE-2025-52448 | HIGH 8.1 | tableau tableau_server Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Server: | 0.3% | — |
| CVE-2025-52447 | HIGH 8.1 | tableau tableau_server Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Se | 0.4% | — |
| CVE-2025-50177 | HIGH 8.1 | microsoft windows_10_1507 Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | 3.9% | — |
| CVE-2025-49735 | HIGH 8.1 | microsoft windows_server_2012 Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. | 1.1% | — |
| CVE-2025-49552 | HIGH 8.1 | adobe connect Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a high-privileged attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user inte | 0.4% | — |
| CVE-2025-49201 | HIGH 8.1 | fortinet fortipam A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to | 0.6% | — |
| CVE-2025-48769 | HIGH 8.1 | apache nuttx Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer variables allowed arbitrary user provided size buffer reallocation and write to the | 1.5% | — |
| CVE-2025-47411 | HIGH 8.1 | apache streampipes A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator. This vulnerability allows an attac | 15.0% | — |
| CVE-2025-46762 | HIGH 8.1 | apache parquet Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code. While 1.15.1 introduced a fix to restrict untrusted packages, the default setting of trusted packages still allows malicious | 1.5% | — |
| CVE-2025-39889 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on incoming connection This is required for passing GAP/SEC/SEM/BI-04-C PTS test case: Security Mode 4 Level 4, Responder - Invalid Encryption K | 0.1% | — |
| CVE-2025-37973 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix out-of-bounds access during multi-link element defragmentation Currently during the multi-link element defragmentation process, the multi-link element length added to the | 0.3% | — |
| CVE-2025-36546 | HIGH 8.1 | f5 f5os-a On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance Mode; access via SSH key-based authentication is still allowed. For an attacker to exploit this vulnerability t | 0.4% | — |
| CVE-2025-33072 | HIGH 8.1 | microsoft msagsfeedback.azurewebsites.net Improper access control in Azure allows an unauthorized attacker to disclose information over a network. | 1.7% | — |
| CVE-2025-33071 | HIGH 8.1 | microsoft windows_server_2012 Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. | 17.3% | — |
| CVE-2025-33070 | HIGH 8.1 | microsoft windows_10_1507 Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network. | 7.0% | — |
| CVE-2025-33054 | HIGH 8.1 | microsoft windows_11_22h2 Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2025-32710 | HIGH 8.1 | microsoft windows_server_2008 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.0% | — |