58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-52964 | MED 6.5 | juniper junos A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When the device receives a specific BGP UPDATE pac | 0.3% | — |
| CVE-2025-52961 | MED 6.5 | juniper junos_os_evolved An Uncontrolled Resource Consumption vulnerability in the Connectivity Fault Management (CFM) daemon and the Connectivity Fault Management Manager (cfmman) of Juniper Networks Junos OS Evolved on PTX10001-36MR, PTX10002-36QDD, PTX10004, PTX10008, PTX10016 all | 0.5% | — |
| CVE-2025-52955 | MED 6.5 | juniper junos An Incorrect Calculation of Buffer Size vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause a memory corruption that leads to a rpd crash. When th | 0.3% | — |
| CVE-2025-52953 | MED 6.5 | juniper junos An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a valid BGP UPDATE packet to cause a BGP session reset, resulting in a Denia | 0.3% | — |
| CVE-2025-52952 | MED 6.5 | juniper junos An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on MX Series with MPC-BUILTIN, MPC1 through MPC9 line cards allows an unauthenticated adjacent attacker to send a malformed packet to the device | 0.3% | — |
| CVE-2025-52949 | MED 6.5 | juniper junos An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a logically adjacent BGP peer sending a specifically malformed BGP packet to cause rpd to crash a | 0.3% | — |
| CVE-2025-52947 | MED 6.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks Junos OS on specific end-of-life (EOL) ACX Series platforms allows an attacker to crash the Forwarding Engine Board (FEB) by flapping an interface, leading to | 0.3% | — |
| CVE-2025-52450 | MED 6.5 | tableau tableau_server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (abdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal.This issue affects Tableau Serv | 0.4% | — |
| CVE-2025-50172 | MED 6.5 | microsoft windows_10_1809 Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network. | 1.5% | — |
| CVE-2025-50166 | MED 6.5 | microsoft windows_10_1507 Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose information over a network. | 1.4% | — |
| CVE-2025-50154 | MED 6.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. | 30.2% | — |
| CVE-2025-49706 | MED 6.5 | ransomware microsoft sharepoint_enterprise_server Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 99.1% | |
| CVE-2025-49681 | MED 6.5 | microsoft windows_server_2008 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2025-49671 | MED 6.5 | microsoft windows_server_2008 Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2025-49670 | MED 6.5 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2025-48977 | MED 6.5 | apache ignite Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can read any file on the server with "cmd=log" command and a log path crafted in a certain way. This issue affects Apache Ignite: from 2.0.0 through 2.17.0. Users a | 0.5% | — |
| CVE-2025-48912 | MED 6.5 | apache superset An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unauthorized a | 0.7% | — |
| CVE-2025-48802 | MED 6.5 | microsoft windows_11_22h2 Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2025-48768 | MED 6.5 | apache nuttx Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to a debug assert trigger (that is disabled by default), NULL pointer dereference ( | 0.8% | — |
| CVE-2025-47997 | MED 6.5 | microsoft sql_server_2016 Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2025-47995 | MED 6.5 | microsoft azure_machine_learning Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2025-47978 | MED 6.5 | microsoft windows_server_2022 Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. | 2.0% | — |
| CVE-2025-47150 | MED 6.5 | f5 f5os-a When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.4% | — |
| CVE-2025-47148 | MED 6.5 | f5 big-ip_access_policy_manager When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource util | 0.4% | — |
| CVE-2025-46548 | MED 6.5 | akka akka_management If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to | 0.7% | — |