IT
57.436 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync

CVE Tracker

57.436 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-48840 MED 5.3 fortinet fortiweb An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unauthenticated attacker to bypass hostname restrictions via a sp 0.5%
CVE-2025-48459 MED 5.3 apache iotdb Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, which fixes the issue. 0.5%
CVE-2025-47294 MED 5.3 fortinet fortios A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the csfd daemon via a specially crafted request. 0.8%
CVE-2025-46647 MED 5.3 apache apisix A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugin with introspection mode 2. The auth service connected to openid-connect provide 0.4%
CVE-2025-46215 MED 5.3 fortinet fortisandbox An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to evade th 0.3%
CVE-2025-3940 MED 5.3 tridium niagara Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15. 0.4%
CVE-2025-3939 MED 5.3 tridium niagara Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10. 0.3%
CVE-2025-36081 MED 5.3 ibm concert IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log input. 0.2%
CVE-2025-36047 MED 5.3 ibm websphere_application_server IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. 0.5%
CVE-2025-33142 MED 5.3 ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections. 0.3%
CVE-2025-32098 MED 5.3 samsung magician An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process. 0.2%
CVE-2025-31672 MED 5.3 apache poi Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (incl 1.3%
CVE-2025-30657 MED 5.3 juniper junos An Improper Encoding or Escaping of Output vulnerability in the Sampling Route Record Daemon (SRRD) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a device configured for flow-monitoring 0.4%
CVE-2025-27906 MED 5.3 ibm content_navigator IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read ob 0.3%
CVE-2025-27367 MED 5.3 ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness of fields for GRC Objects when an authenticated user sends a specially crafted payload to the 0.2%
CVE-2025-25255 MED 5.3 fortinet fortios An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0.1 through 7.0.22 m 0.4%
CVE-2025-25248 MED 5.3 fortinet fortios An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 0.5%
CVE-2025-25007 MED 5.3 microsoft exchange_server Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0.8%
CVE-2025-25006 MED 5.3 microsoft exchange_server Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0.9%
CVE-2025-22859 MED 5.3 fortinet forticlientems A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests. 0.6%
CVE-2025-21597 MED 5.3 juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, logically adjacent BGP peer to cause Denial of Service (DoS). On all Junos OS a 0.2%
CVE-2025-21259 MED 5.3 microsoft outlook Microsoft Outlook Spoofing Vulnerability 1.1%
CVE-2025-21253 MED 5.3 microsoft edge Microsoft Edge for IOS and Android Spoofing Vulnerability 1.2%
CVE-2025-20336 MED 5.3 cisco desk_phone_9841_firmware A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnera 0.4%
CVE-2025-20335 MED 5.3 cisco desk_phone_9841_firmware A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to write arbitrary files on an affected device. This vulnerability 0.4%