58.450 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.450 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-14612 | MED 6.7 | intel quartus_prime Insecure Temporary File vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows : Use of Predictable File Names.This issue affects Quartus Prime Pro: from 24.1 through 25.1.1. | 0.1% | — |
| CVE-2025-14605 | MED 6.7 | intel quartus_prime Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 17.0 through 25.1.1. | 0.1% | — |
| CVE-2025-14599 | MED 6.7 | intel quartus_prime Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Prime Lite Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 23.1 through 2 | 0.1% | — |
| CVE-2025-14596 | MED 6.7 | intel quartus_prime Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 24.1 through 24.3.1. | 0.1% | — |
| CVE-2025-13670 | MED 6.7 | intel high_level_synthesis_compiler The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability | 0.1% | — |
| CVE-2025-13669 | MED 6.7 | intel high_level_synthesis_compiler Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hijacking.This issue affects High Level Synthesis Compiler: from 19.1 through 24.3. | 0.1% | — |
| CVE-2025-13668 | MED 6.7 | intel quartus_prime A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege. | 0.1% | — |
| CVE-2025-13665 | MED 6.7 | intel quartus_prime The System Console Utility for Windows is vulnerable to a DLL planting vulnerability | 0.1% | — |
| CVE-2025-13664 | MED 6.7 | intel quartus_prime A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege. | 0.1% | — |
| CVE-2025-13663 | MED 6.7 | intel quartus_prime Under certain circumstances, the Quartus Prime Pro Installer for Windows does not check the permissions of the Quartus target installation directory if the target installation directory already exists. | 0.1% | — |
| CVE-2024-56497 | MED 6.7 | fortinet fortimail An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attack | 0.6% | — |
| CVE-2024-55955 | MED 6.7 | trendmicro deep_security_agent An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtai | 0.1% | — |
| CVE-2024-54025 | MED 6.7 | fortinet fortiisolator An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator CLI before version 2.4.6 allows a privileged attacker to execute unauthorized code or commands via crafted CLI reques | 0.4% | — |
| CVE-2024-52968 | MED 6.7 | fortinet forticlient An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password. | 0.2% | — |
| CVE-2024-49044 | MED 6.7 | microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-47495 | MED 6.7 | juniper junos_os_evolved An Authorization Bypass Through User-Controlled Key vulnerability allows a locally authenticated attacker with shell access to gain full control of the device when Dual Routing Engines (REs) are in use on Juniper Networks Junos OS Evolved devices. This issue | 0.2% | — |
| CVE-2024-46663 | MED 6.7 | fortinet fortimail A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands. | 0.2% | — |
| CVE-2024-45325 | MED 6.7 | fortinet fortiddos-f An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F version 7.0.0 through 7.02 and before 6.6.3 may allow a privileged attacker to execute unauthorized code or commands | 0.5% | — |
| CVE-2024-43646 | MED 6.7 | microsoft windows_10_1607 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-43645 | MED 6.7 | microsoft windows_10_1507 Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2024-43631 | MED 6.7 | microsoft windows_10_21h2 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-40587 | MED 6.7 | fortinet fortivoice An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthorized code or | 0.6% | — |
| CVE-2024-40586 | MED 6.7 | fortinet forticlient An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe. | 0.2% | — |
| CVE-2024-38668 | MED 6.7 | intel quartus_prime Uncontrolled search path for some Intel(R) Quartus(R) Prime Standard Edition software for Windows before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2024-38383 | MED 6.7 | intel quartus_prime Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition software for Windows before version 24.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |