IT
56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.960 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-21376 HIGH 8.1 microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 9.4%
CVE-2025-21309 HIGH 8.1 microsoft windows_server_2012 Windows Remote Desktop Services Remote Code Execution Vulnerability 15.0%
CVE-2025-21297 HIGH 8.1 microsoft windows_server_2008 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.4%
CVE-2025-21295 HIGH 8.1 microsoft windows_10_1507 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability 1.6%
CVE-2025-21294 HIGH 8.1 microsoft windows_10_1507 Microsoft Digest Authentication Remote Code Execution Vulnerability 1.2%
CVE-2025-21224 HIGH 8.1 microsoft windows_10_21h2 Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability 1.9%
CVE-2025-1915 HIGH 8.1 google chrome Improper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted Chrome Extensi 0.4%
CVE-2025-13639 HIGH 8.1 google chrome Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low) 0.3%
CVE-2025-13316 HIGH 8.1 lynxtechnology twonky_server Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and 2.7%
CVE-2025-13148 HIGH 8.1 ibm aspera_orchestrator IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password. 0.3%
CVE-2025-1290 HIGH 8.1 google chrome_os A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during an AF_VSOCK connect syscall can occur before a wo 0.3%
CVE-2025-11458 HIGH 8.1 google chrome Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2024-8535 HIGH 8.1 citrix netscaler_application_delivery_controller Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources  0.4%
CVE-2024-8534 HIGH 8.1 citrix netscaler_application_delivery_controller Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) a 0.6%
CVE-2024-57973 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 32bit The "gl->tot_len" variable is controlled by the user. It comes from process_responses(). On 32bit systems, the "gl->tot_len + sizeof 0.6%
CVE-2024-56627 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read An offset from client could be a negative value, It could lead to an out-of-bounds read from the stream_buf. Note that this issue is co 0.6%
CVE-2024-50215 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: assign dh_key to NULL after kfree_sensitive ctrl->dh_key might be used across multiple calls to nvmet_setup_dhgroup() for the same controller. So it's better to nullify it after 0.6%
CVE-2024-49132 HIGH 8.1 microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.1%
CVE-2024-49128 HIGH 8.1 microsoft windows_server_2012 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. 1.2%
CVE-2024-49127 HIGH 8.1 microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1.3%
CVE-2024-49126 HIGH 8.1 microsoft windows_10_1507 Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability 1.3%
CVE-2024-49124 HIGH 8.1 microsoft windows_10_1507 Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability 1.4%
CVE-2024-49123 HIGH 8.1 microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.1%
CVE-2024-49122 HIGH 8.1 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 20.4%
CVE-2024-49120 HIGH 8.1 microsoft windows_server_2012 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.1%