IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-24063 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.7%
CVE-2025-24062 HIGH 7.8 microsoft windows_10_21h2 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-24061 HIGH 7.8 microsoft windows_10_1507 Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally. 1.2%
CVE-2025-24060 HIGH 7.8 microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-24059 HIGH 7.8 microsoft windows_10_1507 Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-24058 HIGH 7.8 microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-24057 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 1.0%
CVE-2025-24052 HIGH 7.8 microsoft windows_10_1507 Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumula 2.4%
CVE-2025-24050 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-24048 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-24046 HIGH 7.8 microsoft windows_10_1507 Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-24044 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-23315 HIGH 7.8 nvidia nemo NVIDIA NeMo Framework for all platforms contains a vulnerability in the export and deploy component, where malicious data created by an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution, escala 0.2%
CVE-2025-23304 HIGH 7.8 nvidia nemo NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit of this vulnerability may lead to remote 1.1%
CVE-2025-23303 HIGH 7.8 nvidia nemo NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering. 0.6%
CVE-2025-23158 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add check to handle incorrect queue size qsize represents size of shared queued between driver and video firmware. Firmware can modify this value to an invalid large value 0.2%
CVE-2025-23157 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi_parser: add check to avoid out of bound access There is a possibility that init_codecs is invoked multiple times during manipulated payload from video firmware. In such cas 0.2%
CVE-2025-23156 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi_parser: refactor hfi packet parsing logic words_count denotes the number of words in total payload, while data points to payload of various property within it. When words_c 0.2%
CVE-2025-23151 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Fix race between unprepare and queue_buf A client driver may use mhi_unprepare_from_transfer() to quiesce incoming data during the client driver's tear down. The client drive 0.1%
CVE-2025-23150 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ext4: fix off-by-one error in do_split Syzkaller detected a use-after-free issue in ext4_insert_dentry that was caused by out-of-bounds access due to incorrect splitting in do_split. BUG: K 0.2%
CVE-2025-23142 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: sctp: detect and prevent references to a freed transport in sendmsg sctp_sendmsg() re-uses associations and transports when possible by doing a lookup based on the socket endpoint and the me 0.2%
CVE-2025-23141 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses Acquire a lock on kvm->srcu when userspace is getting MP state to handle a rather extreme edge case where "accepti 0.2%
CVE-2025-22126 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: md: fix mddev uaf while iterating all_mddevs list While iterating all_mddevs list from md_notify_reboot() and md_exit(), list_for_each_entry_safe is used, and this can race with deletint the 0.2%
CVE-2025-22124 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: md/md-bitmap: fix wrong bitmap_limit for clustermd when write sb In clustermd, separate write-intent-bitmaps are used for each cluster node: 0 4k 8k 0.2%
CVE-2025-22115 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: fix block group refcount race in btrfs_create_pending_block_groups() Block group creation is done in two phases, which results in a slightly unintuitive property: a block group can be 0.1%