57.970 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.970 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-27165 | MED 5.5 | adobe substance_3d_stager Substance3D - Stager versions 3.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0.2% | — |
| CVE-2025-27164 | MED 5.5 | adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR | 0.4% | — |
| CVE-2025-27163 | MED 5.5 | adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR | 0.4% | — |
| CVE-2025-26636 | MED 5.5 | microsoft windows_11_24h2 Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2025-25193 | MED 5.5 | netty netty Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows applica | 0.4% | — |
| CVE-2025-24992 | MED 5.5 | microsoft windows_10_1507 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally. | 1.0% | — |
| CVE-2025-24991 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | 2.0% | |
| CVE-2025-24814 | MED 5.5 | apache solr Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are running without authenticatio | 1.2% | — |
| CVE-2025-24449 | MED 5.5 | adobe illustrator Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue | 0.2% | — |
| CVE-2025-24448 | MED 5.5 | adobe illustrator Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue | 0.2% | — |
| CVE-2025-24431 | MED 5.5 | adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR | 0.4% | — |
| CVE-2025-24069 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-24068 | MED 5.5 | microsoft windows_10_1507 Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-24065 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-23163 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: vlan: don't propagate flags on open With the device instance lock, there is now a possibility of a deadlock: [ 1.211455] ============================================ [ 1.211571] | 0.2% | — |
| CVE-2025-23162 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Don't try to trigger a full GT reset if VF VFs don't have access to the GDRST(0x941c) register that driver uses to reset a GT. Attempt to trigger a reset using debugfs: $ cat /s | 0.2% | — |
| CVE-2025-23161 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: PCI: vmd: Make vmd_dev::cfg_lock a raw_spinlock_t type The access to the PCI config space via pci_ops::read and pci_ops::write is a low-level hardware access. The functions can be accessed w | 0.1% | — |
| CVE-2025-23160 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization On Mediatek devices with a system companion processor (SCP) the mtk_scp structure has to be remove | 0.2% | — |
| CVE-2025-23154 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: io_uring/net: fix io_req_post_cqe abuse by send bundle [ 114.987980][ T5313] WARNING: CPU: 6 PID: 5313 at io_uring/io_uring.c:872 io_req_post_cqe+0x12e/0x4f0 [ 114.991597][ T5313] RIP: 001 | 0.2% | — |
| CVE-2025-23153 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: arm/crc-t10dif: fix use of out-of-scope array in crc_t10dif_arch() Fix a silly bug where an array was used outside of its scope. | 0.2% | — |
| CVE-2025-23152 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: arm64/crc-t10dif: fix use of out-of-scope array in crc_t10dif_arch() Fix a silly bug where an array was used outside of its scope. | 0.2% | — |
| CVE-2025-23149 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tpm: do not start chip while suspended Checking TPM_CHIP_FLAG_SUSPENDED after the call to tpm_find_get_ops() can lead to a spurious tpm_chip_start() call: [35985.503771] i2c i2c-1: Transfer | 0.2% | — |
| CVE-2025-23148 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: soc: samsung: exynos-chipid: Add NULL pointer check in exynos_chipid_probe() soc_dev_attr->revision could be NULL, thus, a pointer check is added to prevent potential NULL pointer dereferenc | 0.2% | — |
| CVE-2025-23147 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: i3c: Add NULL pointer check in i3c_master_queue_ibi() The I3C master driver may receive an IBI from a target device that has not been probed yet. In such cases, the master calls `i3c_master_ | 0.2% | — |
| CVE-2025-23146 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: mfd: ene-kb3930: Fix a potential NULL pointer dereference The off_gpios could be NULL. Add missing check in the kb3930_probe(). This is similar to the issue fixed in commit b1ba8bcb2d1f ("ba | 0.2% | — |