58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-38342 | HIGH 7.0 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: software node: Correct a OOB check in software_node_get_reference_args() software_node_get_reference_args() wants to get @index-th element, so the property value requires at least '(index + | 0.2% | — |
| CVE-2025-37984 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() Herbert notes that DIV_ROUND_UP() may overflow unnecessarily if an ecdsa implementation's ->key_size() callback returns an | 0.2% | — |
| CVE-2025-37876 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfs: Only create /proc/fs/netfs with CONFIG_PROC_FS When testing a special config: CONFIG_NETFS_SUPPORTS=y CONFIG_PROC_FS=n The system crashes with something like: [ 3.766197] ------ | 0.3% | — |
| CVE-2025-30378 | HIGH 7.0 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | 1.4% | — |
| CVE-2025-29973 | HIGH 7.0 | microsoft azure_file_sync Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-29841 | HIGH 7.0 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-27732 | HIGH 7.0 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-27492 | HIGH 7.0 | microsoft windows_11_22h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-27478 | HIGH 7.0 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-27475 | HIGH 7.0 | microsoft windows_11_22h2 Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-27468 | HIGH 7.0 | microsoft windows_10_1507 Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-26665 | HIGH 7.0 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-26649 | HIGH 7.0 | microsoft windows_11_22h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-26640 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-26633 | HIGH 7.0 | ransomware microsoft windows_10_1507 Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. | 30.4% | |
| CVE-2025-26627 | HIGH 7.0 | microsoft azure_arc Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally. | 0.9% | — |
| CVE-2025-24983 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | 1.3% | |
| CVE-2025-24916 | HIGH 7.0 | tenable nessus_network_monitor When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secure | 0.1% | — |
| CVE-2025-24078 | HIGH 7.0 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-24070 | HIGH 7.0 | microsoft asp.net_core Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2025-24036 | HIGH 7.0 | microsoft autoupdate Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2025-23132 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: f2fs: quota: fix to avoid warning in dquot_writeback_dquots() F2FS-fs (dm-59): checkpoint=enable has some unwritten data. ------------[ cut here ]------------ WARNING: CPU: 6 PID: 8013 at f | 0.3% | — |
| CVE-2025-21932 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm: abort vma_modify() on merge out of memory failure The remainder of vma_modify() relies upon the vmg state remaining pristine after a merge attempt. Usually this is the case, however in | 0.2% | — |
| CVE-2025-21915 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cdx: Fix possible UAF error in driver_override_show() Fixed a possible UAF problem in driver_override_show() in drivers/cdx/cdx.c This function driver_override_show() is part of DEVICE_ATTR | 0.2% | — |
| CVE-2025-21414 | HIGH 7.0 | microsoft windows_10_1507 Windows Core Messaging Elevation of Privileges Vulnerability | 0.6% | — |