IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-53134 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-5180 HIGH 7.0 wondershare filmora A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue is some unknown functionality in the library CRYPTBASE.dll of the file NFWCHK.exe of the component Installer. The manipulation leads to unc 0.3% —
CVE-2025-50174 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-50167 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-50158 HIGH 7.0 microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally. 0.4% —
CVE-2025-49762 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-49744 HIGH 7.0 microsoft windows_10_1507 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.8% —
CVE-2025-49737 HIGH 7.0 microsoft teams Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2025-49734 HIGH 7.0 microsoft powershell Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-49727 HIGH 7.0 microsoft windows_10_1507 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-49699 HIGH 7.0 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.3% —
CVE-2025-49685 HIGH 7.0 microsoft windows_10_1809 Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-49678 HIGH 7.0 microsoft windows_10_1507 Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2025-49677 HIGH 7.0 microsoft windows_11_22h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 1.0% —
CVE-2025-47989 HIGH 7.0 microsoft azure_connected_machine_agent Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. 0.6% —
CVE-2025-47975 HIGH 7.0 microsoft windows_10_1507 Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-4540 HIGH 7.0 lodop c-lodop A vulnerability was found in MTSoftware C-Lodop 6.6.1.1 on Windows. It has been rated as critical. This issue affects some unknown processing of the component CLodopPrintService. The manipulation leads to unquoted search path. The attack needs to be approached 0.3% —
CVE-2025-4525 HIGH 7.0 discord discord A vulnerability, which was classified as critical, has been found in Discord 1.0.9188 on Windows. Affected by this issue is some unknown functionality in the library WINSTA.dll. The manipulation leads to uncontrolled search path. The attack needs to be approac 0.3% —
CVE-2025-39905 HIGH 7.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: phylink: add lock for serializing concurrent pl->phydev writes with resolver Currently phylink_resolve() protects itself against concurrent phylink_bringup_phy() or phylink_disconnect_p 0.1% —
CVE-2025-39776 HIGH 7.0 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: mm/debug_vm_pgtable: clear page table entries at destroy_args() The mm/debug_vm_pagetable test allocates manually page table entries for the tests it runs, using also its manually allocated 0.1% —
CVE-2025-39759 HIGH 7.0 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix race between quota disable and quota rescan ioctl There's a race between a task disabling quotas and another running the rescan ioctl that can result in a use-after-free o 0.1% —
CVE-2025-39749 HIGH 7.0 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: rcu: Protect ->defer_qs_iw_pending from data race On kernels built with CONFIG_IRQ_WORK=y, when rcu_read_unlock() is invoked within an interrupts-disabled region of code [1], it will invoke 0.2% —
CVE-2025-38584 HIGH 7.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: padata: Fix pd UAF once and for all There is a race condition/UAF in padata_reorder that goes back to the initial commit. A reference count is taken at the start of the process in padata_do 0.2% —
CVE-2025-38461 HIGH 7.0 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_* TOCTOU Transport assignment may race with module unload. Protect new_transport from becoming a stale pointer. This also takes care of an insecure call in vsock_use_lo 0.1% —
CVE-2025-38460 HIGH 7.0 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix potential null-ptr-deref in to_atmarpd(). atmarpd is protected by RTNL since commit f3a0592b37b8 ("[ATM]: clip causes unregister hang"). However, it is not enough because to_ 0.2% —