IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-38342 HIGH 7.0 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: software node: Correct a OOB check in software_node_get_reference_args() software_node_get_reference_args() wants to get @index-th element, so the property value requires at least '(index + 0.2% —
CVE-2025-37984 HIGH 7.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() Herbert notes that DIV_ROUND_UP() may overflow unnecessarily if an ecdsa implementation's ->key_size() callback returns an 0.2% —
CVE-2025-37876 HIGH 7.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfs: Only create /proc/fs/netfs with CONFIG_PROC_FS When testing a special config: CONFIG_NETFS_SUPPORTS=y CONFIG_PROC_FS=n The system crashes with something like: [ 3.766197] ------ 0.3% —
CVE-2025-30378 HIGH 7.0 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. 1.4% —
CVE-2025-29973 HIGH 7.0 microsoft azure_file_sync Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-29841 HIGH 7.0 microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-27732 HIGH 7.0 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-27492 HIGH 7.0 microsoft windows_11_22h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-27478 HIGH 7.0 microsoft windows_10_1507 Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. 0.5% —
CVE-2025-27475 HIGH 7.0 microsoft windows_11_22h2 Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-27468 HIGH 7.0 microsoft windows_10_1507 Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2025-26665 HIGH 7.0 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-26649 HIGH 7.0 microsoft windows_11_22h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-26640 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. 0.5% —
CVE-2025-26633 HIGH 7.0 ransomware microsoft windows_10_1507 Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. 30.4%
CVE-2025-26627 HIGH 7.0 microsoft azure_arc Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally. 0.9% —
CVE-2025-24983 HIGH 7.0 microsoft windows_10_1507 Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. 1.3%
CVE-2025-24916 HIGH 7.0 tenable nessus_network_monitor When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secure 0.1% —
CVE-2025-24078 HIGH 7.0 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6% —
CVE-2025-24070 HIGH 7.0 microsoft asp.net_core Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. 1.0% —
CVE-2025-24036 HIGH 7.0 microsoft autoupdate Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability 0.4% —
CVE-2025-23132 HIGH 7.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: f2fs: quota: fix to avoid warning in dquot_writeback_dquots() F2FS-fs (dm-59): checkpoint=enable has some unwritten data. ------------[ cut here ]------------ WARNING: CPU: 6 PID: 8013 at f 0.3% —
CVE-2025-21932 HIGH 7.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm: abort vma_modify() on merge out of memory failure The remainder of vma_modify() relies upon the vmg state remaining pristine after a merge attempt. Usually this is the case, however in 0.2% —
CVE-2025-21915 HIGH 7.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cdx: Fix possible UAF error in driver_override_show() Fixed a possible UAF problem in driver_override_show() in drivers/cdx/cdx.c This function driver_override_show() is part of DEVICE_ATTR 0.2% —
CVE-2025-21414 HIGH 7.0 microsoft windows_10_1507 Windows Core Messaging Elevation of Privileges Vulnerability 0.6% —