IT
57.551 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.551 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2025-52446 HIGH 8.0 tableau tableau_server Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulation (data access to the production database cluster).This issue affects Tableau Server: before 2025.1. 0.2%
CVE-2025-52436 HIGH 8.8 fortinet fortisandbox An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all ver 6.5%
CVE-2025-52435 HIGH 7.5 apache nimble J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to 0.2%
CVE-2025-52434 HIGH 7.5 apache tomcat Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue aff 1.9%
CVE-2025-5180 HIGH 7.0 wondershare filmora A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue is some unknown functionality in the library CRYPTBASE.dll of the file NFWCHK.exe of the component Installer. The manipulation leads to unc 0.3%
CVE-2025-50213 CRIT 9.8 apache apache-airflow-providers-snowflake Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were ad 0.6%
CVE-2025-50177 HIGH 8.1 microsoft windows_10_1507 Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. 3.9%
CVE-2025-50176 HIGH 7.8 microsoft windows_11_22h2 Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execute code locally. 0.5%
CVE-2025-50175 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-50174 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-50173 HIGH 7.8 microsoft windows_10_1507 Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-50172 MED 6.5 microsoft windows_10_1809 Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network. 1.4%
CVE-2025-50171 CRIT 9.1 microsoft windows_server_2022 Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network. 1.0%
CVE-2025-50170 HIGH 7.8 microsoft windows_10_1809 Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-50169 HIGH 7.5 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2025-50168 HIGH 7.8 microsoft windows_11_22h2 Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 0.8%
CVE-2025-50167 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-50166 MED 6.5 microsoft windows_10_1507 Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose information over a network. 1.3%
CVE-2025-50165 CRIT 9.8 microsoft windows_11_24h2 Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. 9.5%
CVE-2025-50164 HIGH 8.0 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0.9%
CVE-2025-50163 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2025-50162 HIGH 8.0 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0.9%
CVE-2025-50161 HIGH 7.3 microsoft windows_10_1507 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-50160 HIGH 8.0 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0.9%
CVE-2025-50159 HIGH 7.3 microsoft windows_10_1507 Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally. 0.6%