IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.571 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-67895 CRIT 9.8 apache apache-airflow-providers-edge3 Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow 2 has been always development-only and not officially relea 1.0%
CVE-2025-6543 CRIT 9.8 citrix netscaler_application_delivery_controller Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server 10.1%
CVE-2025-64657 CRIT 9.8 microsoft azure_application_gateway Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2025-64446 CRIT 9.8 fortinet fortiweb A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands 91.8%
CVE-2025-64155 CRIT 9.8 fortinet fortisiem An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 43.2%
CVE-2025-61622 CRIT 9.8 apache fory Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. An application is vulnerable if it reads pyfory serialized data from untrusted sourc 41.3%
CVE-2025-60724 CRIT 9.8 microsoft 365_copilot Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. 5.9%
CVE-2025-60021 CRIT 9.8 apache brpc Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. Root Cause: The bRPC heap profiler built-in service (/pprof/heap) does not validate t 24.8%
CVE-2025-59719 CRIT 9.8 fortinet fortiweb An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML 25.0%
CVE-2025-59718 CRIT 9.8 fortinet fortios A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, 63.4%
CVE-2025-59390 CRIT 9.8 apache druid Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this case, the secret is generated using `ThreadLocalRandom`, which is not a crypto-gr 0.7%
CVE-2025-59287 CRIT 9.8 microsoft windows_server_2012 Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. 99.9%
CVE-2025-59246 CRIT 9.8 microsoft entra_id Azure Entra ID Elevation of Privilege Vulnerability 7.2%
CVE-2025-59245 CRIT 9.8 microsoft sharepoint_online Microsoft SharePoint Online Elevation of Privilege Vulnerability 1.1%
CVE-2025-59059 CRIT 9.8 apache ranger Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue. 1.2%
CVE-2025-55232 CRIT 9.8 microsoft hpc_pack Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. 2.1%
CVE-2025-54947 CRIT 9.8 apache streampark In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely conf 0.5%
CVE-2025-54539 CRIT 9.8 apache activemq_nms_amqp A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2.3.0, when establishing connections to untrusted AMQP servers. Malicious servers 2.1%
CVE-2025-54466 CRIT 9.8 apache ofbiz Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can exploit th 15.0%
CVE-2025-53770 CRIT 9.8 ransomware microsoft sharepoint_server Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a co 100.0%
CVE-2025-53766 CRIT 9.8 microsoft 365_copilot Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. 7.1%
CVE-2025-53763 CRIT 9.8 microsoft purview_data_governance Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2025-53606 CRIT 9.8 apache seata Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recommended to upgrade to version 2.5.0, which fixes the issue. 0.6%
CVE-2025-53521 CRIT 9.8 f5 big-ip_access_policy_manager When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 2.2%
CVE-2025-50213 CRIT 9.8 apache apache-airflow-providers-snowflake Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were ad 0.6%