IT
58.535 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.535 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-64784 HIGH 7.1 adobe dng_software_development_kit DNG SDK versions 1.7.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure or application denial of service. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitat 0.2% —
CVE-2025-62676 HIGH 7.1 fortinet forticlient An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privil 0.2% —
CVE-2025-62570 HIGH 7.1 microsoft windows_11_24h2 Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally. 0.4% —
CVE-2025-62202 HIGH 7.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5% —
CVE-2025-60726 HIGH 7.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.6% —
CVE-2025-59235 HIGH 7.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.7% —
CVE-2025-59232 HIGH 7.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5% —
CVE-2025-59208 HIGH 7.1 microsoft windows_10_1507 Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network. 0.5% —
CVE-2025-54905 HIGH 7.1 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.6% —
CVE-2025-53760 HIGH 7.1 microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. 16.5% —
CVE-2025-48821 HIGH 7.1 microsoft windows_10_1507 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network. 0.5% —
CVE-2025-48819 HIGH 7.1 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network. 0.4% —
CVE-2025-47959 HIGH 7.1 microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network. 10.7% —
CVE-2025-40082 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() BUG: KASAN: slab-out-of-bounds in hfsplus_uni2asc+0xa71/0xb90 fs/hfsplus/unicode.c:186 Read of size 2 at addr ffff8880289ef218 by ta 0.2% —
CVE-2025-39957 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: increase scan_ies_len for S1G Currently the S1G capability element is not taken into account for the scan_ies_len, which leads to a buffer length validation failure in ieee80 0.2% —
CVE-2025-39928 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: i2c: rtl9300: ensure data length is within supported range Add an explicit check for the xfer length to 'rtl9300_i2c_config_xfer' to ensure the data length isn't within the supported range. 0.1% —
CVE-2025-39922 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix incorrect map used in eee linkmode incorrectly used ixgbe_lp_map in loops intended to populate the supported and advertised EEE linkmode bitmaps based on ixgbe_ls_map. This result 0.1% —
CVE-2025-39902 HIGH 7.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: mm/slub: avoid accessing metadata when pointer is invalid in object_err() object_err() reports details of an object for further debugging, such as the freelist pointer, redzone, etc. However 0.2% —
CVE-2025-39901 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: i40e: remove read access to debugfs files The 'command' and 'netdev_ops' debugfs files are a legacy debugging interface supported by the i40e driver since its early days by commit 02e9c29081 0.2% —
CVE-2025-39891 HIGH 7.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Initialize the chan_stats array to zero The adapter->chan_stats[] array is initialized in mwifiex_init_channel_scan_gap() with vmalloc(), which doesn't zero out memory. The a 0.2% —
CVE-2025-39883 HIGH 7.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory When I did memory failure tests, below panic occurs: page dumped because: VM_BUG_ON_PAGE(PagePoisoned(page)) k 0.2% —
CVE-2025-39853 HIGH 7.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: i40e: Fix potential invalid access when MAC list is empty list_first_entry() never returns NULL - if the list is empty, it still returns a pointer to an invalid object, leading to potential 0.2% —
CVE-2025-39840 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: audit: fix out-of-bounds read in audit_compare_dname_path() When a watch on dir=/ is combined with an fsnotify event for a single-character name directly under / (e.g., creating /a), an out- 0.1% —
CVE-2025-39817 HIGH 7.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare Observed on kernel 6.6 (present on master as well): BUG: KASAN: slab-out-of-bounds in memcmp+0x98/0xd0 Call trace: kasan_check_ 0.2% —
CVE-2025-39778 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: objtool, nvmet: Fix out-of-bounds stack access in nvmet_ctrl_state_show() The csts_state_names[] array only has six sparse entries, but the iteration code in nvmet_ctrl_state_show() iterates 0.3% —