IT
57.588 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.588 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-27470 HIGH 7.5 microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. 2.3%
CVE-2025-27469 HIGH 7.5 microsoft windows_10_1507 Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. 2.5%
CVE-2025-27091 HIGH 7.5 cisco openh264 OpenH264 is a free license codec library which supports H.264 encoding and decoding. A vulnerability in the decoding functions of OpenH264 codec library could allow a remote, unauthenticated attacker to trigger a heap overflow. This vulnerability is due to a r 0.7%
CVE-2025-26864 HIGH 7.5 apache iotdb Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. User 0.7%
CVE-2025-26795 HIGH 7.5 apache iotdb Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommen 0.7%
CVE-2025-26687 HIGH 7.5 microsoft 365_copilot Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. 1.1%
CVE-2025-26686 HIGH 7.5 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network. 1.5%
CVE-2025-26682 HIGH 7.5 microsoft asp.net_core Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. 1.7%
CVE-2025-26680 HIGH 7.5 microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. 2.0%
CVE-2025-26677 HIGH 7.5 microsoft windows_server_2016 Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network. 1.7%
CVE-2025-26673 HIGH 7.5 microsoft windows_10_1507 Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. 2.5%
CVE-2025-26668 HIGH 7.5 microsoft windows_10_1507 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 1.2%
CVE-2025-26652 HIGH 7.5 microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. 2.3%
CVE-2025-26641 HIGH 7.5 microsoft windows_10_1507 Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. 2.2%
CVE-2025-26634 HIGH 7.5 microsoft windows_10_1507 Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2025-26413 HIGH 7.5 apache kvrocks Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it will cause the server to crash due to its index is  out of range. This issue aff 0.7%
CVE-2025-25253 HIGH 7.5 fortinet fortios An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 0.1%
CVE-2025-24853 HIGH 7.5 apache jspwiki A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Further research by the JSPWiki team s 0.5%
CVE-2025-24783 HIGH 7.5 apache cocoon ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon. This issue affects Apache Cocoon: all versions. When a continuation is created, it gets a random identifier. Because the random 0.8%
CVE-2025-24497 HIGH 7.5 f5 big-ip_policy_enforcement_manager When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.4%
CVE-2025-24326 HIGH 7.5 f5 big-ip_application_security_manager When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 0.4%
CVE-2025-24312 HIGH 7.5 f5 big-ip_advanced_firewall_manager When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, undisclosed traffic can cause an increase in CPU resource utilization.   Note: Software versions which have re 0.4%
CVE-2025-24043 HIGH 7.5 microsoft windbg Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network. 0.9%
CVE-2025-23412 HIGH 7.5 f5 big-ip_access_policy_manager When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.4%
CVE-2025-23331 HIGH 7.5 nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a memory allocation with excessive size value, leading to a segmentation fault, by providing an invalid request. A successful exploit of this vulnerability m 0.6%