IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-29868 MED 6.5 apache answer Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private 0.9% —
CVE-2025-29836 MED 6.5 microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.3% —
CVE-2025-29835 MED 6.5 microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.3% —
CVE-2025-29832 MED 6.5 microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.3% —
CVE-2025-29830 MED 6.5 microsoft windows_10_1507 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.3% —
CVE-2025-29825 MED 6.5 microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.8% —
CVE-2025-29806 MED 6.5 microsoft edge_chromium No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.9% —
CVE-2025-27738 MED 6.5 microsoft windows_10_1507 Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network. 3.4% —
CVE-2025-27555 MED 6.5 apache airflow Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, values of those variables 0.4% —
CVE-2025-27526 MED 6.5 apache inlong Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability which can lead to JDBC Vulnerability URLEncdoe and backspace bypass. Users are advised to upgrade to Apache InLon 0.8% —
CVE-2025-27522 MED 6.5 apache inlong Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is a secondary mining bypass for CVE-2024-26579. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry- 0.8% —
CVE-2025-27474 MED 6.5 microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.8% —
CVE-2025-27391 MED 6.5 apache artemis Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled. This issu 0.4% —
CVE-2025-27017 MED 6.5 apache nifi Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance events of those proces 1.2% —
CVE-2025-26685 MED 6.5 microsoft defender_for_identity Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network. 0.7% —
CVE-2025-26676 MED 6.5 microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.6% —
CVE-2025-26672 MED 6.5 microsoft windows_10_1507 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.8% —
CVE-2025-26667 MED 6.5 microsoft windows_server_2008 Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.8% —
CVE-2025-26664 MED 6.5 microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.8% —
CVE-2025-26651 MED 6.5 microsoft windows_11_22h2 Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. 2.5% —
CVE-2025-26635 MED 6.5 microsoft windows_10_1809 Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network. 1.5% —
CVE-2025-25539 MED 6.5 onespan vasco_self-service_portal Local File Inclusion vulnerability in Vasco v3.14and before allows a remote attacker to obtain sensitive information via help menu. 0.4% —
CVE-2025-25069 MED 6.5 apache kvrocks A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, whi 0.8% —
CVE-2025-25005 MED 6.5 microsoft exchange_server Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. 1.4% —
CVE-2025-24996 MED 6.5 microsoft windows_10_1507 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. 1.3% —