58.450 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.450 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-48807 | MED 6.7 | microsoft windows_10_1607 Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-48803 | MED 6.7 | microsoft windows_10_1507 Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-48418 | MED 6.7 | fortinet fortianalyzer A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, FortiAnalyzer 7.0.0 through 7.0.14, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnaly | 0.5% | — |
| CVE-2025-47857 | MED 6.7 | fortinet fortiweb A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via craf | 0.5% | — |
| CVE-2025-47179 | MED 6.7 | microsoft configuration_manager_2403 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-47171 | MED 6.7 | microsoft 365_apps Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. | 1.7% | — |
| CVE-2025-33231 | MED 6.7 | nvidia cuda_toolkit NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker could cause an uncontrolled search path element by exploiting insecure DLL search paths. A successful exploit of this vulnerability might le | 0.2% | — |
| CVE-2025-30650 | MED 6.7 | juniper junos A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. This issue affects systems running Junos OS using Linux-based | 0.1% | — |
| CVE-2025-27759 | MED 6.7 | fortinet fortiweb An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and before 7.0.10 allows an authenticated privilege | 0.4% | — |
| CVE-2025-27488 | MED 6.7 | microsoft windows_hardware_lab_kit Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-26684 | MED 6.7 | microsoft defender_for_endpoint External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-26681 | MED 6.7 | microsoft windows_10_21h2 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-23355 | MED 6.7 | nvidia nsight_graphics NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL highjacking attack. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and denia | 0.2% | — |
| CVE-2025-22862 | MED 6.7 | fortinet fortios An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an a | 0.3% | — |
| CVE-2025-21357 | MED 6.7 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2025-21199 | MED 6.7 | microsoft azure_agent Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-20313 | MED 6.7 | cisco ios_xe Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. | 0.2% | — |
| CVE-2025-20201 | MED 6.7 | cisco ios_xe A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input | 0.2% | — |
| CVE-2025-20200 | MED 6.7 | cisco ios_xe A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input | 0.2% | — |
| CVE-2025-20197 | MED 6.7 | cisco ios_xe A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input | 0.2% | — |
| CVE-2025-20177 | MED 6.7 | cisco ios_xr A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR image signature verification and load unverified software on an affected device. To exploit this vulnerability, the attacker must h | 0.2% | — |
| CVE-2025-20143 | MED 6.7 | cisco ios_xr A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure Boot functionality and load unverified software on an affected device. To exploit this vulnerability, the attack | 0.1% | — |
| CVE-2025-14917 | MED 6.7 | ibm websphere_application_server IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings. | 0.4% | — |
| CVE-2025-14625 | MED 6.7 | intel quartus_prime Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell modules), Altera Quartus Prime Lite on Windows (Nios II Command Shell modules) allows Search Order Hijacking.This issue affects Quartus Prime Stan | 0.1% | — |
| CVE-2025-14614 | MED 6.7 | intel quartus_prime Insecure Temporary File vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Prime Lite Installer (SFX) on Windows allows Explore for Predictable Temporary File Names.This issue affects Quartus Prime Standard: from | 0.1% | — |