IT
57.924 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.924 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-26681 MED 6.7 microsoft windows_10_21h2 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-23355 MED 6.7 nvidia nsight_graphics NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL highjacking attack. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and denia 0.2%
CVE-2025-22862 MED 6.7 fortinet fortios An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an a 0.3%
CVE-2025-21357 MED 6.7 microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability 0.6%
CVE-2025-21199 MED 6.7 microsoft azure_agent Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-20313 MED 6.7 Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. 0.2%
CVE-2025-20201 MED 6.7 cisco ios_xe A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input 0.2%
CVE-2025-20200 MED 6.7 cisco ios_xe A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input 0.2%
CVE-2025-20197 MED 6.7 cisco ios_xe A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input 0.2%
CVE-2025-20177 MED 6.7 cisco ios_xr A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR image signature verification and load unverified software on an affected device. To exploit this vulnerability, the attacker must h 0.2%
CVE-2025-20143 MED 6.7 cisco ios_xr A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure Boot functionality and load unverified software on an affected device. To exploit this vulnerability, the attack 0.1%
CVE-2025-14917 MED 6.7 ibm websphere_application_server IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings. 0.4%
CVE-2025-14625 MED 6.7 intel quartus_prime Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell modules), Altera Quartus Prime Lite on Windows (Nios II Command Shell modules) allows Search Order Hijacking.This issue affects Quartus Prime Stan 0.1%
CVE-2025-14614 MED 6.7 intel quartus_prime Insecure Temporary File vulnerability in Altera Quartus Prime Standard  Installer (SFX) on Windows, Altera Quartus Prime Lite  Installer (SFX) on Windows allows Explore for Predictable Temporary File Names.This issue affects Quartus Prime Standard: from 0.1%
CVE-2025-14612 MED 6.7 intel quartus_prime Insecure Temporary File vulnerability in Altera Quartus Prime Pro  Installer (SFX) on Windows allows : Use of Predictable File Names.This issue affects Quartus Prime Pro: from 24.1 through 25.1.1. 0.1%
CVE-2025-14605 MED 6.7 intel quartus_prime Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 17.0 through 25.1.1. 0.1%
CVE-2025-14599 MED 6.7 intel quartus_prime Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Prime Lite  Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 23.1 through 2 0.1%
CVE-2025-14596 MED 6.7 intel quartus_prime Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 24.1 through 24.3.1. 0.1%
CVE-2025-13670 MED 6.7 intel high_level_synthesis_compiler The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability 0.1%
CVE-2025-13669 MED 6.7 intel high_level_synthesis_compiler Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hijacking.This issue affects High Level Synthesis Compiler: from 19.1 through 24.3. 0.1%
CVE-2025-13668 MED 6.7 intel quartus_prime A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege. 0.1%
CVE-2025-13665 MED 6.7 intel quartus_prime The System Console Utility for Windows is vulnerable to a DLL planting vulnerability 0.1%
CVE-2025-13664 MED 6.7 intel quartus_prime A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege. 0.1%
CVE-2025-13663 MED 6.7 intel quartus_prime Under certain circumstances, the Quartus Prime Pro Installer for Windows does not check the permissions of the Quartus target installation directory if the target installation directory already exists. 0.1%
CVE-2024-56497 MED 6.7 fortinet fortimail An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attack 0.6%