57.490 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.490 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2025-54813 | HIGH 7.5 | apache log4cxx Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contains certain non-printable characters, these will be passed along in the message an | 1.3% | — |
| CVE-2025-54812 | MED 5.4 | apache log4cxx Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not properly escaped when writing out to the HTML file. If untrusted data is used to retrieve the name of a logger, an attacker could theoretical | 1.2% | — |
| CVE-2025-54809 | HIGH 7.4 | f5 f5_access F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.3% | — |
| CVE-2025-54805 | MED 6.5 | f5 big-ip_next_cloud-native_network_functions When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization. Note: Software versions which have reached End o | 0.3% | — |
| CVE-2025-5480 | HIGH 7.8 | action1 agent Action1 Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Action1. An attacker must first obtain the ability to execute low-privileged code | 0.3% | — |
| CVE-2025-54755 | MED 4.9 | f5 big-ip_access_policy_manager A directory traversal vulnerability exists in TMUI that allows a highly privileged authenticated attacker to access files which are not limited to the intended files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 1.1% | — |
| CVE-2025-54660 | MED 5.5 | fortinet forticlient An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve the saved VPN user p | 0.2% | — |
| CVE-2025-54659 | MED 5.8 | fortinet fortisoar_agent_communication_bridge An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated at | 0.5% | — |
| CVE-2025-54658 | HIGH 7.8 | fortinet fortidlp_agent An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1 | 0.2% | — |
| CVE-2025-54656 | MED 6.5 | apache struts_extras ** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affects Apache Struts Extras: before 2. When using LookupDispatchAction, in some cases, Struts may print untrusted input to the logs without an | 0.6% | — |
| CVE-2025-54550 | HIGH 8.1 | apache airflow The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be exploited to allow UI user who had access to modify XComs to perform arbitrary execution of code on the worker. S | 0.6% | — |
| CVE-2025-54539 | CRIT 9.8 | apache activemq_nms_amqp A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2.3.0, when establishing connections to untrusted AMQP servers. Malicious servers | 2.1% | — |
| CVE-2025-54500 | MED 5.3 | f5 big-ip_access_policy_manager An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoT | 0.5% | — |
| CVE-2025-54479 | HIGH 7.5 | f5 big-ip_next_cloud-native_network_functions When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) | 0.3% | — |
| CVE-2025-54472 | HIGH 7.5 | apache brpc Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows attackers to crash the service via network. Root Cause: In the bRPC Redis protocol parser code, memory for arrays or strings of corresponding | 1.2% | — |
| CVE-2025-54466 | CRIT 9.8 | apache ofbiz Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can exploit th | 16.4% | — |
| CVE-2025-54353 | MED 5.4 | fortinet fortisandbox An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all ver | 6.3% | — |
| CVE-2025-54293 | MED 6.5 | canonical lxd Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symbolic links. | 0.6% | — |
| CVE-2025-54290 | MED 5.3 | canonical lxd Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints. | 0.3% | — |
| CVE-2025-54288 | MED 6.8 | canonical lxd Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers and obtain their metadata, configuration, and device informati | 0.4% | — |
| CVE-2025-54287 | MED 6.5 | canonical lxd Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 templa | 0.4% | — |
| CVE-2025-54286 | HIGH 8.8 | canonical lxd Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication. | 0.1% | — |
| CVE-2025-54284 | HIGH 7.8 | adobe illustrator Illustrator versions 29.7, 28.7.9 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open | 0.2% | — |
| CVE-2025-54283 | HIGH 7.8 | adobe illustrator Illustrator versions 29.7, 28.7.9 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open | 0.2% | — |
| CVE-2025-54282 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2020.9, 2022.7 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vic | 0.2% | — |