IT
57.490 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.490 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2025-54912 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-54911 HIGH 7.3 microsoft windows_10_1507 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-54910 HIGH 8.4 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54908 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54907 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-54906 HIGH 7.8 microsoft 365_apps Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally. 0.7%
CVE-2025-54905 HIGH 7.1 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2025-54904 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54903 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54902 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54901 MED 5.5 microsoft 365_apps Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2025-54900 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54899 HIGH 7.8 microsoft 365_apps Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54898 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54897 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 19.1%
CVE-2025-54896 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54895 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-54894 HIGH 7.8 microsoft windows_10_1507 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability 0.4%
CVE-2025-54858 HIGH 7.5 f5 big-ip_advanced_web_application_firewall When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security policy is applied to a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Sof 0.3%
CVE-2025-54854 HIGH 7.5 f5 big-ip_access_policy_manager When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not eval 0.3%
CVE-2025-54838 MED 6.8 fortinet fortiportal An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests. 0.3%
CVE-2025-54831 MED 6.5 apache airflow Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connection fields to Connection Editing Users, effectively applying a "write-only" model for sensitive values. In Air 0.9%
CVE-2025-54822 MED 4.3 fortinet fortios An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.8, FortiOS 7.0.0 through 7.0.11, FortiProxy 7.4.0 through 7.4.8, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiP 0.3%
CVE-2025-54821 LOW 1.9 fortinet fortios An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all version 0.2%
CVE-2025-54820 HIGH 8.1 fortinet fortimanager A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via 0.9%