56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-30398 | HIGH 8.1 | microsoft nuance_powerscribe_360 Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2025-30391 | HIGH 8.1 | microsoft dynamics_365_customer_service Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2025-29828 | HIGH 8.1 | microsoft windows_11_22h2 Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network. | 1.2% | — |
| CVE-2025-27482 | HIGH 8.1 | microsoft windows_server_2016 Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 1.7% | — |
| CVE-2025-27480 | HIGH 8.1 | microsoft windows_server_2012 Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 12.3% | — |
| CVE-2025-26683 | HIGH 8.1 | microsoft azure_playwright Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-26671 | HIGH 8.1 | microsoft windows_server_2008 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.2% | — |
| CVE-2025-26670 | HIGH 8.1 | microsoft windows_10_1507 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | 10.4% | — |
| CVE-2025-26663 | HIGH 8.1 | microsoft windows_10_1507 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | 1.9% | — |
| CVE-2025-26521 | HIGH 8.1 | apache cloudstack When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of the caller account are used to create the secret config in the CKS-based Kubernetes cluster. A member of the p | 0.6% | — |
| CVE-2025-25249 | HIGH 8.1 | fortinet fortios A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7. | 0.8% | — |
| CVE-2025-24472 | HIGH 8.1 | ransomware fortinet fortios An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream an | 7.0% | |
| CVE-2025-24064 | HIGH 8.1 | microsoft windows_server_2008 Use after free in DNS Server allows an unauthorized attacker to execute code over a network. | 1.4% | — |
| CVE-2025-24045 | HIGH 8.1 | microsoft windows_server_2012 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.4% | — |
| CVE-2025-24035 | HIGH 8.1 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.8% | — |
| CVE-2025-23319 | HIGH 8.1 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write by sending a request. A successful exploit of this vulnerability might lead to remote code execution, deni | 1.6% | — |
| CVE-2025-23318 | HIGH 8.1 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, data tamperin | 0.7% | — |
| CVE-2025-22043 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for durable handle context Add missing bounds check for durable handle context. | 0.5% | — |
| CVE-2025-22042 | HIGH 8.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for create lease context Add missing bounds check for create lease context. | 0.5% | — |
| CVE-2025-21947 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix type confusion via race condition when using ipc_msg_send_request req->handle is allocated using ksmbd_acquire_id(&ipc_ida), based on ida_alloc. req->handle from ksmbd_ipc_login_r | 0.4% | — |
| CVE-2025-21766 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv4: use RCU protection in __ip_rt_update_pmtu() __ip_rt_update_pmtu() must use RCU protection to make sure the net structure it reads does not disappear. | 0.5% | — |
| CVE-2025-21765 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU protection in ip6_default_advmss() ip6_default_advmss() needs rcu protection to make sure the net structure it reads does not disappear. | 0.6% | — |
| CVE-2025-21762 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF. | 0.6% | — |
| CVE-2025-21760 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU protection in ndisc_send_skb() ndisc_send_skb() can be called without RTNL or RCU held. Acquire rcu_read_lock() earlier, so that we can use dev_net_rcu() and avoid a poten | 36.8% | — |
| CVE-2025-21659 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netdev: prevent accessing NAPI instances from another namespace The NAPI IDs were not fully exposed to user space prior to the netlink API, so they were never namespaced. The netlink API mus | 0.2% | — |