IT
56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.960 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-66467 HIGH 8.0 apache cloudstack Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, the previous owners can gain unauthorized read and write access 0.4%
CVE-2025-64660 HIGH 8.0 microsoft visual_studio_code Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. 0.6%
CVE-2025-62452 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0.8%
CVE-2025-62204 HIGH 8.0 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 2.1%
CVE-2025-60715 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0.8%
CVE-2025-53786 HIGH 8.0 microsoft exchange_server On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following furt 7.4%
CVE-2025-53720 HIGH 8.0 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0.9%
CVE-2025-52446 HIGH 8.0 tableau tableau_server Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulation (data access to the production database cluster).This issue affects Tableau Server: before 2025.1. 0.2%
CVE-2025-50164 HIGH 8.0 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0.8%
CVE-2025-50162 HIGH 8.0 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0.8%
CVE-2025-50160 HIGH 8.0 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0.8%
CVE-2025-49691 HIGH 8.0 microsoft windows_10_1507 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network. 0.5%
CVE-2025-47972 HIGH 8.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2025-47178 HIGH 8.0 microsoft configuration_manager_2503 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network. 2.9%
CVE-2025-39860 HIGH 8.0 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() syzbot reported the splat below without a repro. In the splat, a single thread calling bt_accept_dequeue() freed sk and touched 0.2%
CVE-2025-27487 HIGH 8.0 microsoft remote_desktop_client Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network. 1.4%
CVE-2025-26646 HIGH 8.0 microsoft .net External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. 1.2%
CVE-2025-24320 HIGH 8.0 f5 big-ip_access_policy_manager A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. This vulnerability is due to an incomplete fix for CV 0.4%
CVE-2025-21400 HIGH 8.0 microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability 34.5%
CVE-2025-20386 HIGH 8.0 splunk splunk In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Splunk Enterprise for Windows Installation directory. This lets n 0.5%
CVE-2025-20298 HIGH 8.0 splunk universal_forwarder In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by defaul 0.3%
CVE-2025-15558 HIGH 8.0 docker command_line_interface Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx 0.5%
CVE-2025-0118 HIGH 8.0 paloaltonetworks globalprotect A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated use 0.4%
CVE-2024-8069 HIGH 8.0 citrix session_recording Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server 14.6%
CVE-2024-8068 HIGH 8.0 citrix session_recording Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain 1.4%