IT
56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.580 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-36422 MED 4.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 IBM InfoSphere DataStage Flow Designer is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website 0.1%
CVE-2025-3629 MED 4.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's comments due to improper ownership management. 0.2%
CVE-2025-36225 MED 4.3 ibm aspera_faspex IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data. 0.2%
CVE-2025-2827 MED 4.3 ibm sterling_file_gateway IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in further attacks against the system. 0.2%
CVE-2025-27427 MED 4.3 apache artemis A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission fo 0.6%
CVE-2025-27369 MED 4.3 ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used for the administration of OpenPages. An authenticated user is able to obtain 0.2%
CVE-2025-25250 MED 4.3 fortinet fortios An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiSASE 25.1.c may allow 0.5%
CVE-2025-25045 MED 4.3 ibm infosphere_information_server IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system. 0.3%
CVE-2025-25001 MED 4.3 microsoft edge Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.7%
CVE-2025-24055 MED 4.3 microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack. 0.9%
CVE-2025-23419 MED 4.3 debian debian_linux When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://ngin 2.7%
CVE-2025-22829 MED 4.3 apache cloudstack The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone with authenticated user-account access in CloudStack 4.20.0.0 environments, where this plugin is enabled and have access to specific APIs can enable or disable r 0.7%
CVE-2025-22828 MED 4.3 apache cloudstack CloudStack users can add and read comments (annotations) on resources they are authorised to access.  Due to an access validation issue that affects Apache CloudStack versions from 4.16.0, users who have access, prior access or knowledge of resource UUIDs can 2.0%
CVE-2025-22220 MED 4.3 vmware aria_operations_for_logs VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user. 0.3%
CVE-2025-21404 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 1.1%
CVE-2025-21332 MED 4.3 microsoft windows_10_1507 MapUrlToZone Security Feature Bypass Vulnerability 1.5%
CVE-2025-21329 MED 4.3 microsoft windows_10_1507 MapUrlToZone Security Feature Bypass Vulnerability 1.5%
CVE-2025-21328 MED 4.3 microsoft windows_10_1507 MapUrlToZone Security Feature Bypass Vulnerability 1.5%
CVE-2025-21269 MED 4.3 microsoft windows_10_1507 Windows HTML Platforms Security Feature Bypass Vulnerability 4.6%
CVE-2025-21268 MED 4.3 microsoft windows_10_1507 MapUrlToZone Security Feature Bypass Vulnerability 2.0%
CVE-2025-21247 MED 4.3 microsoft windows_10_1507 Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. 3.2%
CVE-2025-21219 MED 4.3 microsoft windows_10_1507 MapUrlToZone Security Feature Bypass Vulnerability 3.0%
CVE-2025-21189 MED 4.3 microsoft windows_10_1507 MapUrlToZone Security Feature Bypass Vulnerability 3.0%
CVE-2025-20346 MED 4.3 cisco catalyst_center A vulnerability in Cisco Catalyst Center could allow an authenticated, remote attacker to execute operations that should require Administrator privileges. The attacker would need valid read-only user credentials. This vulnerability is due to improper role-b 0.3%
CVE-2025-20326 MED 4.3 cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an unauthenticated, remote attacker to conduct a cross-site request f 0.2%