57.551 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-21314 | MED 6.5 | microsoft windows_10_1607 Windows SmartScreen Spoofing Vulnerability | 1.4% | — |
| CVE-2025-21313 | MED 6.5 | microsoft windows_11_24h2 Windows Security Account Manager (SAM) Denial of Service Vulnerability | 1.6% | — |
| CVE-2025-21308 | MED 6.5 | microsoft windows_10_1507 Windows Themes Spoofing Vulnerability | 2.2% | — |
| CVE-2025-21301 | MED 6.5 | microsoft windows_10_1507 Windows Geolocation Service Information Disclosure Vulnerability | 1.6% | — |
| CVE-2025-21288 | MED 6.5 | microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability | 0.7% | — |
| CVE-2025-21283 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2025-21279 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2025-21272 | MED 6.5 | microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability | 0.7% | — |
| CVE-2025-21254 | MED 6.5 | microsoft windows_10_1607 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.0% | — |
| CVE-2025-21217 | MED 6.5 | microsoft windows_10_1507 Windows NTLM Spoofing Vulnerability | 1.9% | — |
| CVE-2025-21216 | MED 6.5 | microsoft windows_10_1607 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.0% | — |
| CVE-2025-21212 | MED 6.5 | microsoft windows_10_1607 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.0% | — |
| CVE-2025-21203 | MED 6.5 | microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.6% | — |
| CVE-2025-21197 | MED 6.5 | microsoft windows_10_1507 Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content. | 3.2% | — |
| CVE-2025-21193 | MED 6.5 | microsoft windows_server_2016 Active Directory Federation Server Spoofing Vulnerability | 0.8% | — |
| CVE-2025-21185 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2025-20376 | MED 6.5 | cisco unified_contact_center_express A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is due to an insufficient input validation associated to file upload mechanisms. An attacker could exp | 0.4% | — |
| CVE-2025-20375 | MED 6.5 | cisco unified_contact_center_express A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is due to an insufficient input validation associated to specific UI features. An attacker could explo | 0.4% | — |
| CVE-2025-20362 | MED 6.5 | cisco adaptive_security_appliance_software Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to u | 87.1% | |
| CVE-2025-20344 | MED 6.5 | cisco nexus_dashboard A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. This vulnerability is due to insufficient validation of the contents of a ba | 0.6% | — |
| CVE-2025-20301 | MED 6.5 | cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-privileged, remote attacker to access troubleshoot files for a different domain. This vulnerability is due to missing authorization checks. | 0.4% | — |
| CVE-2025-20284 | MED 6.5 | cisco identity_services_engine A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. | 16.1% | — |
| CVE-2025-20283 | MED 6.5 | cisco identity_services_engine A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. | 8.3% | — |
| CVE-2025-20269 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker to retrieve arbitrary files from the underlying file system | 0.4% | — |
| CVE-2025-20257 | MED 6.5 | cisco secure_network_analytics A vulnerability in an API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with low privileges to generate fraudulent findings that are used to generate alarms | 0.3% | — |