57.588 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.588 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-30651 | HIGH 7.5 | juniper junos A Buffer Access with Incorrect Length Value vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When an attacker sends a spec | 0.4% | — |
| CVE-2025-30649 | HIGH 7.5 | juniper junos An Improper Input Validation vulnerability in the syslog stream TCP transport of Juniper Networks Junos OS on MX240, MX480 and MX960 devices with MX-SPC3 Security Services Card allows an unauthenticated, network-based attacker, to send specific spoofed packets | 0.4% | — |
| CVE-2025-30645 | HIGH 7.5 | juniper junos A NULL Pointer Dereference vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker causing specific, valid control traffic to be sent out of a Dual-Stack (DS) Lite tunnel to crash the flowd process, resulting in a | 0.4% | — |
| CVE-2025-30644 | HIGH 7.5 | juniper junos A Heap-based Buffer Overflow vulnerability in the flexible PIC concentrator (FPC) of Juniper Networks Junos OS on EX2300, EX3400, EX4100, EX4300, EX4300MP, EX4400, EX4600, EX4650-48Y, and QFX5k Series allows an attacker to send a specific DHCP packet to the de | 0.3% | — |
| CVE-2025-30399 | HIGH 7.5 | microsoft .net Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-30397 | HIGH 7.5 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. | 26.8% | |
| CVE-2025-29971 | HIGH 7.5 | microsoft windows_11_22h2 Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network. | 64.4% | — |
| CVE-2025-29969 | HIGH 7.5 | microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2025-29847 | HIGH 7.5 | apache linkis A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if the URL parameter configured on the frontend has undergone multiple rounds of URL encoding, it may bypass the | 0.8% | — |
| CVE-2025-29842 | HIGH 7.5 | microsoft windows_10_1507 Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network. | 0.4% | — |
| CVE-2025-29834 | HIGH 7.5 | microsoft edge_chromium Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-29831 | HIGH 7.5 | microsoft windows_server_2008 Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-29816 | HIGH 7.5 | microsoft 365_apps Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network. | 0.5% | — |
| CVE-2025-29810 | HIGH 7.5 | microsoft windows_10_1507 Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. | 2.5% | — |
| CVE-2025-29805 | HIGH 7.5 | microsoft outlook Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network. | 1.5% | — |
| CVE-2025-27820 | HIGH 7.5 | apache httpclient A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release | 0.9% | — |
| CVE-2025-27819 | HIGH 7.5 | apache kafka In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To exploit th | 1.0% | — |
| CVE-2025-27817 | HIGH 7.5 | apache kafka A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including "sasl.oauthbearer.token.endpoint.url" and " | 68.8% | — |
| CVE-2025-27553 | HIGH 7.5 | apache commons_vfs Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved fil | 1.4% | — |
| CVE-2025-27533 | HIGH 7.5 | apache activemq Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of | 8.7% | — |
| CVE-2025-27486 | HIGH 7.5 | microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | 2.1% | — |
| CVE-2025-27485 | HIGH 7.5 | microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | 2.1% | — |
| CVE-2025-27484 | HIGH 7.5 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-27479 | HIGH 7.5 | microsoft windows_server_2012 Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network. | 2.2% | — |
| CVE-2025-27473 | HIGH 7.5 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. | 2.2% | — |