57.574 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.574 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-49715 | HIGH 7.5 | microsoft dynamics_365 Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2025-49656 | HIGH 7.5 | apache jena Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue. | 1.5% | — |
| CVE-2025-49630 | HIGH 7.5 | apache http_server In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured f | 1.2% | — |
| CVE-2025-49506 | HIGH 7.5 | apache apr-util APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as | 0.4% | — |
| CVE-2025-49125 | HIGH 7.5 | apache tomcat Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That pat | 3.5% | — |
| CVE-2025-48989 | HIGH 7.5 | apache tomcat Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, | 3.5% | — |
| CVE-2025-48988 | HIGH 7.5 | apache tomcat Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time th | 59.5% | — |
| CVE-2025-48976 | HIGH 7.5 | apache commons_fileupload Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrad | 62.6% | — |
| CVE-2025-48814 | HIGH 7.5 | microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network. | 1.0% | — |
| CVE-2025-48431 | HIGH 7.5 | apache thrift Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted request | 1.1% | — |
| CVE-2025-48392 | HIGH 7.5 | apache iotdb A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to upgrade to version 2.0.5, which fixes the issue. | 0.6% | — |
| CVE-2025-48008 | HIGH 7.5 | f5 big-ip_access_policy_manager When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which hav | 0.4% | — |
| CVE-2025-47988 | HIGH 7.5 | microsoft azure_monitor_agent Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network. | 0.9% | — |
| CVE-2025-47984 | HIGH 7.5 | microsoft windows_10_1507 Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network. | 16.2% | — |
| CVE-2025-47867 | HIGH 7.5 | trendmicro apex_central A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to remote code execution on affected installations. | 1.8% | — |
| CVE-2025-47865 | HIGH 7.5 | trendmicro apex_central A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on affected installations. | 1.7% | — |
| CVE-2025-46774 | HIGH 7.5 | fortinet forticlient An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related executable | 0.1% | — |
| CVE-2025-46706 | HIGH 7.5 | f5 big-ip_access_policy_manager When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.4% | — |
| CVE-2025-46405 | HIGH 7.5 | f5 big-ip_access_policy_manager When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.3% | — |
| CVE-2025-4365 | HIGH 7.5 | citrix netscaler_console Arbitrary file read in NetScaler Console and NetScaler SDX (SVM) | 9.2% | — |
| CVE-2025-41433 | HIGH 7.5 | f5 big-ip_access_policy_manager When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: | 0.4% | — |
| CVE-2025-41431 | HIGH 7.5 | f5 big-ip_access_policy_manager When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in the standby BIG-IP systems in a traffic group. Note: Software versions which have reached End of Technical S | 0.4% | — |
| CVE-2025-41430 | HIGH 7.5 | f5 big-ip_ssl_orchestrator When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.3% | — |
| CVE-2025-41414 | HIGH 7.5 | f5 big-ip_access_policy_manager When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.4% | — |
| CVE-2025-41399 | HIGH 7.5 | f5 big-ip_access_policy_manager When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluate | 0.4% | — |