IT
57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.620 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-36631 HIGH 8.4 tenable nessus_agent In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege. 0.2%
CVE-2025-36630 HIGH 8.4 tenable nessus In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege. 0.2%
CVE-2025-34191 HIGH 8.4 vasion virtual_appliance_application Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (macOS/Linux client deployments) contain an arbitrary file write vulnerability via the response file handling. When tasks produce output t 0.3%
CVE-2025-33225 HIGH 8.4 nvidia nvidia_resiliency_extension NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predictable log-file names. A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, inf 0.3%
CVE-2025-33067 HIGH 8.4 microsoft windows_10_1507 Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally. 0.5%
CVE-2025-32717 HIGH 8.4 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-32704 HIGH 8.4 microsoft 365_apps Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-30386 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.7%
CVE-2025-30377 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-26678 HIGH 8.4 microsoft windows_10_1809 Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally. 0.5%
CVE-2025-24084 HIGH 8.4 microsoft windows_11_22h2 Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally. 0.7%
CVE-2025-24049 HIGH 8.4 microsoft azure_command-line_interface Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally. 0.4%
CVE-2025-23159 HIGH 8.4 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add a check to handle OOB in sfr region sfr->buf_size is in shared memory and can be modified by malicious user. OOB write is possible when the size is made higher than ac 0.2%
CVE-2025-22121 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all() There's issue as follows: BUG: KASAN: use-after-free in ext4_xattr_inode_dec_ref_all+0x6ff/0x790 Read of size 4 at addr ffff8880 0.2%
CVE-2025-22080 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Prevent integer overflow in hdr_first_de() The "de_off" and "used" variables come from the disk so they both need to check. The problem is that on 32bit systems if they're both gr 0.2%
CVE-2025-21362 HIGH 8.4 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.9%
CVE-2025-21354 HIGH 8.4 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.9%
CVE-2024-56704 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: 9p/xen: fix release of IRQ Kernel logs indicate an IRQ was double-freed. Pass correct device ID during IRQ release. [Dominique: remove confusing variable reset to 0] 0.2%
CVE-2024-56684 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-cmdq: fix wrong use of sizeof in cmdq_get_clocks() It should be size of the struct clk_bulk_data, not data pointer pass to devm_kcalloc(). 0.2%
CVE-2024-56373 HIGH 8.4 apache airflow DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context, which they should normally not be able to do, leading to potentially remote code execution in the con 1.0%
CVE-2024-55639 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: renesas: rswitch: avoid use-after-put for a device tree node The device tree node saved in the rswitch_device structure is used at several driver locations. So passing this node to of_n 0.2%
CVE-2024-53092 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio_pci: Fix admin vq cleanup by using correct info pointer vp_modern_avq_cleanup() and vp_del_vqs() clean up admin vq resources by virtio_pci_vq_info pointer. The info pointer of admin v 0.2%
CVE-2024-53082 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio_net: Add hash_key_length check Add hash_key_length check in virtnet_probe() to avoid possible out of bound errors when setting/reading the hash key. 0.2%
CVE-2024-51459 HIGH 8.4 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions. 0.1%
CVE-2024-50115 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory Ignore nCR3[4:0] when loading PDPTEs from memory for nested SVM, as bits 4:0 of CR3 are ignored when PAE paging is used, and thus 0.2%