58.535 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.535 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-21742 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usbnet: ipheth: use static NDP16 location in URB Original code allowed for the start of NDP16 to be anywhere within the URB based on the `wNdpIndex` value in NTH16. Only the start position o | 0.2% | — |
| CVE-2025-21741 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usbnet: ipheth: fix DPE OoB read Fix an out-of-bounds DPE read, limit the number of processed DPEs to the amount that fits into the fixed-size NDP16 header. | 0.2% | — |
| CVE-2025-21719 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipmr: do not call mr_mfc_uses_dev() for unres entries syzbot found that calling mr_mfc_uses_dev() for unres entries would crash [1], because c->mfc_un.res.minvif / c->mfc_un.res.maxvif alias | 0.2% | — |
| CVE-2025-21650 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: hns3: fixed hclge_fetch_pf_reg accesses bar space out of bounds issue The TQP BAR space is divided into two segments. TQPs 0-1023 and TQPs 1024-1279 are in different BAR space addresses | 0.2% | — |
| CVE-2025-21640 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy As mentioned in a previous commit of this series, using the 'net' structure via 'current' is not recommended for different reasons | 0.2% | — |
| CVE-2025-21638 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: auth_enable: avoid using current->nsproxy As mentioned in a previous commit of this series, using the 'net' structure via 'current' is not recommended for different reasons: - | 0.2% | — |
| CVE-2025-21637 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: udp_port: avoid using current->nsproxy As mentioned in a previous commit of this series, using the 'net' structure via 'current' is not recommended for different reasons: - In | 0.2% | — |
| CVE-2025-21419 | HIGH 7.1 | microsoft windows_10_1507 Windows Setup Files Cleanup Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-21391 | HIGH 7.1 | microsoft windows_10_1507 Windows Storage Elevation of Privilege Vulnerability | 2.3% | |
| CVE-2025-21379 | HIGH 7.1 | microsoft windows_11_24h2 DHCP Client Service Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2025-21346 | HIGH 7.1 | microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2025-21299 | HIGH 7.1 | microsoft windows_10_1507 Windows Kerberos Security Feature Bypass Vulnerability | 2.2% | — |
| CVE-2025-21264 | HIGH 7.1 | microsoft visual_studio_code Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0.8% | — |
| CVE-2025-21194 | HIGH 7.1 | microsoft surface_go_2_1901_firmware Microsoft Surface Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2025-20206 | HIGH 7.1 | cisco secure_client A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the Secure Firewall Posture Engine, formerly HostScan, is | 0.2% | — |
| CVE-2025-20113 | HIGH 7.1 | cisco unified_contact_center_express A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges to Administrator for a limited set of functions on an affected system. This vulnerability is due to insufficient server-side validation | 0.4% | — |
| CVE-2025-11791 | HIGH 7.1 | acronis agent Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186, Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) befo | 0.1% | — |
| CVE-2025-11206 | HIGH 7.1 | google chrome Heap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2024-8691 | HIGH 7.1 | paloaltonetworks pan-os A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vuln | 0.3% | — |
| CVE-2024-8687 | HIGH 7.1 | paloaltonetworks globalprotect An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or pass | 0.4% | — |
| CVE-2024-8539 | HIGH 7.1 | ivanti secure_access_client Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files. | 0.2% | — |
| CVE-2024-58238 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Resolve TX timeout error in power save stress test This fixes the tx timeout issue seen while running a stress test on btnxpuart for couple of hours, such that the inte | 0.2% | — |
| CVE-2024-58054 | HIGH 7.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: staging: media: max96712: fix kernel oops when removing module The following kernel oops is thrown when trying to remove the max96712 module: Unable to handle kernel paging request at virtu | 0.2% | — |
| CVE-2024-58015 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix for out-of bound access error Selfgen stats are placed in a buffer using print_array_to_buf_index() function. Array length parameter passed to the function is too big, resu | 0.2% | — |
| CVE-2024-58014 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: brcmsmac: add gain range check to wlc_phy_iqcal_gainparams_nphy() In 'wlc_phy_iqcal_gainparams_nphy()', add gain range check to WARN() instead of possible out-of-bounds 'tbl_iqcal_gain | 0.2% | — |