56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-66467 | HIGH 8.0 | apache cloudstack Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, the previous owners can gain unauthorized read and write access | 0.4% | — |
| CVE-2025-64660 | HIGH 8.0 | microsoft visual_studio_code Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-62452 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-62204 | HIGH 8.0 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.1% | — |
| CVE-2025-60715 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-53786 | HIGH 8.0 | microsoft exchange_server On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following furt | 7.4% | — |
| CVE-2025-53720 | HIGH 8.0 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2025-52446 | HIGH 8.0 | tableau tableau_server Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulation (data access to the production database cluster).This issue affects Tableau Server: before 2025.1. | 0.2% | — |
| CVE-2025-50164 | HIGH 8.0 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-50162 | HIGH 8.0 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-50160 | HIGH 8.0 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-49691 | HIGH 8.0 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2025-47972 | HIGH 8.0 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2025-47178 | HIGH 8.0 | microsoft configuration_manager_2503 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network. | 2.9% | — |
| CVE-2025-39860 | HIGH 8.0 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() syzbot reported the splat below without a repro. In the splat, a single thread calling bt_accept_dequeue() freed sk and touched | 0.2% | — |
| CVE-2025-27487 | HIGH 8.0 | microsoft remote_desktop_client Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network. | 1.4% | — |
| CVE-2025-26646 | HIGH 8.0 | microsoft .net External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. | 1.2% | — |
| CVE-2025-24320 | HIGH 8.0 | f5 big-ip_access_policy_manager A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. This vulnerability is due to an incomplete fix for CV | 0.4% | — |
| CVE-2025-21400 | HIGH 8.0 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 34.5% | — |
| CVE-2025-20386 | HIGH 8.0 | splunk splunk In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Splunk Enterprise for Windows Installation directory. This lets n | 0.5% | — |
| CVE-2025-20298 | HIGH 8.0 | splunk universal_forwarder In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by defaul | 0.3% | — |
| CVE-2025-15558 | HIGH 8.0 | docker command_line_interface Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx | 0.5% | — |
| CVE-2025-0118 | HIGH 8.0 | paloaltonetworks globalprotect A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated use | 0.4% | — |
| CVE-2024-8069 | HIGH 8.0 | citrix session_recording Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server | 14.6% | |
| CVE-2024-8068 | HIGH 8.0 | citrix session_recording Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain | 1.4% |