57.020 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
57.020 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-21632 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Ensure shadow stack is active before "getting" registers The x86 shadow stack support has its own set of registers. Those registers are XSAVE-managed, but they are "supervisor state | 0.2% | — |
| CVE-2025-21596 | MED 5.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in the command-line processing of Juniper Networks Junos OS on SRX1500, SRX4100, and SRX4200 devices allows a local, low-privileged authenticated attacker executing the 'show chassis environment pem' | 0.2% | — |
| CVE-2025-21592 | MED 5.5 | juniper junos An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows a local, low-privileged user with access to the Junos CLI to view the contents of sensitiv | 0.2% | — |
| CVE-2025-21374 | MED 5.5 | microsoft windows_10_1507 Windows CSC Service Information Disclosure Vulnerability | 0.6% | — |
| CVE-2025-21340 | MED 5.5 | microsoft windows_10_1809 Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2025-21323 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21321 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21320 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21319 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21318 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21317 | MED 5.5 | microsoft windows_10_21h2 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21316 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21284 | MED 5.5 | microsoft windows_10_1507 Windows Virtual Trusted Platform Module Denial of Service Vulnerability | 0.7% | — |
| CVE-2025-21280 | MED 5.5 | microsoft windows_10_1507 Windows Virtual Trusted Platform Module Denial of Service Vulnerability | 0.7% | — |
| CVE-2025-21274 | MED 5.5 | microsoft windows_10_1507 Windows Event Tracing Denial of Service Vulnerability | 0.8% | — |
| CVE-2025-21257 | MED 5.5 | microsoft windows_10_1607 Windows WLAN AutoConfig Service Information Disclosure Vulnerability | 0.7% | — |
| CVE-2025-21155 | MED 5.5 | adobe substance_3d_stager Substance3D - Stager versions 3.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-servic | 0.3% | — |
| CVE-2025-21126 | MED 5.5 | adobe indesign InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service condition. An attacker could exploit this vulnerability to cause the application to crash, r | 0.3% | — |
| CVE-2025-21125 | MED 5.5 | adobe indesign InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of | 0.3% | — |
| CVE-2025-21124 | MED 5.5 | adobe indesign InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this | 0.3% | — |
| CVE-2025-20213 | MED 5.5 | cisco catalyst_sd-wan_manager A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. To exploit this vulnerability, the attacker mu | 0.2% | — |
| CVE-2025-13751 | MED 5.5 | openvpn openvpn Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service. | 0.2% | — |
| CVE-2025-1349 | MED 5.5 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus alte | 0.2% | — |
| CVE-2025-12439 | MED 5.5 | google chrome Inappropriate implementation in App-Bound Encryption in Google Chrome on Windows prior to 142.0.7444.59 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium) | 0.1% | — |
| CVE-2025-10221 | MED 5.5 | axxonsoft axxon_one Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via reading TRACE log files conta | 0.1% | — |