58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-24986 | MED 6.5 | microsoft azure_promptflow_core Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2025-24471 | MED 6.5 | fortinet fortios An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate. | 0.4% | — |
| CVE-2025-24319 | MED 6.5 | f5 big-ip_next_central_manager When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes service to terminate. Note: Software versions which have reached End of Technical Suppor | 0.4% | — |
| CVE-2025-24071 | MED 6.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. | 22.9% | — |
| CVE-2025-24054 | MED 6.5 | microsoft windows_10_1507 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | 58.9% | |
| CVE-2025-23408 | MED 6.5 | apache fineract Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0. Users are encouraged to upgrade to version 1.13.0, the latest release. | 0.5% | — |
| CVE-2025-23243 | MED 6.5 | nvidia riva NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to data tampering or denial of service. | 2.1% | — |
| CVE-2025-22258 | MED 6.5 | fortinet fortios A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through | 0.6% | — |
| CVE-2025-21602 | MED 6.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a specific BGP update packet to cause rpd to crash and resta | 0.2% | — |
| CVE-2025-21600 | MED 6.5 | juniper junos An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, logically adjacent BGP peer sending a specifically malformed BGP packet to cause rpd to crash and restart, | 0.2% | — |
| CVE-2025-21595 | MED 6.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause an FPC to crash, leading to Denial of Service (DoS) | 0.3% | — |
| CVE-2025-21593 | MED 6.5 | juniper junos An Improper Control of a Resource Through its Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial-of-Service (DoS). On devices with SR | 0.2% | — |
| CVE-2025-21377 | MED 6.5 | microsoft windows_10_1507 NTLM Hash Disclosure Spoofing Vulnerability | 24.5% | — |
| CVE-2025-21352 | MED 6.5 | microsoft windows_10_1507 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.0% | — |
| CVE-2025-21314 | MED 6.5 | microsoft windows_10_1607 Windows SmartScreen Spoofing Vulnerability | 1.4% | — |
| CVE-2025-21313 | MED 6.5 | microsoft windows_11_24h2 Windows Security Account Manager (SAM) Denial of Service Vulnerability | 1.6% | — |
| CVE-2025-21308 | MED 6.5 | microsoft windows_10_1507 Windows Themes Spoofing Vulnerability | 2.2% | — |
| CVE-2025-21301 | MED 6.5 | microsoft windows_10_1507 Windows Geolocation Service Information Disclosure Vulnerability | 1.6% | — |
| CVE-2025-21288 | MED 6.5 | microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability | 0.7% | — |
| CVE-2025-21283 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2025-21279 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2025-21272 | MED 6.5 | microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability | 0.7% | — |
| CVE-2025-21254 | MED 6.5 | microsoft windows_10_1607 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.0% | — |
| CVE-2025-21217 | MED 6.5 | microsoft windows_10_1507 Windows NTLM Spoofing Vulnerability | 1.9% | — |
| CVE-2025-21216 | MED 6.5 | microsoft windows_10_1607 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.0% | — |