56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-21376 | HIGH 8.1 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 9.4% | — |
| CVE-2025-21309 | HIGH 8.1 | microsoft windows_server_2012 Windows Remote Desktop Services Remote Code Execution Vulnerability | 15.0% | — |
| CVE-2025-21297 | HIGH 8.1 | microsoft windows_server_2008 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2025-21295 | HIGH 8.1 | microsoft windows_10_1507 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2025-21294 | HIGH 8.1 | microsoft windows_10_1507 Microsoft Digest Authentication Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2025-21224 | HIGH 8.1 | microsoft windows_10_21h2 Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2025-1915 | HIGH 8.1 | google chrome Improper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted Chrome Extensi | 0.4% | — |
| CVE-2025-13639 | HIGH 8.1 | google chrome Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low) | 0.3% | — |
| CVE-2025-13316 | HIGH 8.1 | lynxtechnology twonky_server Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and | 2.7% | — |
| CVE-2025-13148 | HIGH 8.1 | ibm aspera_orchestrator IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password. | 0.3% | — |
| CVE-2025-1290 | HIGH 8.1 | google chrome_os A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during an AF_VSOCK connect syscall can occur before a wo | 0.3% | — |
| CVE-2025-11458 | HIGH 8.1 | google chrome Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2024-8535 | HIGH 8.1 | citrix netscaler_application_delivery_controller Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources | 0.4% | — |
| CVE-2024-8534 | HIGH 8.1 | citrix netscaler_application_delivery_controller Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) a | 0.6% | — |
| CVE-2024-57973 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 32bit The "gl->tot_len" variable is controlled by the user. It comes from process_responses(). On 32bit systems, the "gl->tot_len + sizeof | 0.6% | — |
| CVE-2024-56627 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read An offset from client could be a negative value, It could lead to an out-of-bounds read from the stream_buf. Note that this issue is co | 0.6% | — |
| CVE-2024-50215 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: assign dh_key to NULL after kfree_sensitive ctrl->dh_key might be used across multiple calls to nvmet_setup_dhgroup() for the same controller. So it's better to nullify it after | 0.6% | — |
| CVE-2024-49132 | HIGH 8.1 | microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-49128 | HIGH 8.1 | microsoft windows_server_2012 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.2% | — |
| CVE-2024-49127 | HIGH 8.1 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-49126 | HIGH 8.1 | microsoft windows_10_1507 Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-49124 | HIGH 8.1 | microsoft windows_10_1507 Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-49123 | HIGH 8.1 | microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-49122 | HIGH 8.1 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 20.4% | — |
| CVE-2024-49120 | HIGH 8.1 | microsoft windows_server_2012 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.1% | — |