CVE Tracker
Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.
1,539
Total CVEs
1,539
CISA KEV
1539
Critical & High
Mar 9, 2026
Last KEV Update
| CVE ID | Severity | Vendor | Description | Published | KEV |
|---|---|---|---|---|---|
| CVE-2025-12480 | High | GladinetTriofox | Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete. | Nov 12, 2025 | KEV |
| CVE-2025-62215 | High | MicrosoftWindows | Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-level access. | Nov 12, 2025 | KEV |
| CVE-2025-9242 | High | WatchGuardFirebox | WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code. | Nov 12, 2025 | KEV |
| CVE-2025-21042 | High | SamsungMobile Devices | Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code. | Nov 10, 2025 | KEV |
| CVE-2025-11371 | High | GladinetCentreStack and Triofox | Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files. | Nov 4, 2025 | KEV |
| CVE-2025-48703 | High | CWPControl Web Panel | CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known. | Nov 4, 2025 | KEV |
| CVE-2025-41244 | High | BroadcomVMware Aria Operations and VMware Tools | Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM. | Oct 30, 2025 | KEV |
| CVE-2025-24893 | High | XWikiPlatform | XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch. | Oct 30, 2025 | KEV |
| CVE-2025-6204 | High | Dassault SystèmesDELMIA Apriso | Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code. | Oct 28, 2025 | KEV |
| CVE-2025-6205 | High | Dassault SystèmesDELMIA Apriso | Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application. | Oct 28, 2025 | KEV |
| CVE-2025-54236 | High | AdobeCommerce and Magento | Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API. | Oct 24, 2025 | KEV |
| CVE-2025-59287 | High | MicrosoftWindows | Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution. | Oct 24, 2025 | KEV |
| CVE-2025-61932 | High | MotexLANSCOPE Endpoint Manager | Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packets. | Oct 22, 2025 | KEV |
| CVE-2022-48503 | High | AppleMultiple Products | Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. | Oct 20, 2025 | KEV |
| CVE-2025-2746 | High | KenticoXperience CMS | Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects. | Oct 20, 2025 | KEV |
| CVE-2025-2747 | High | KenticoXperience CMS | Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects. | Oct 20, 2025 | KEV |
| CVE-2025-61884 | High | OracleE-Business Suite | Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication. | Oct 20, 2025 | KEV |
| CVE-2025-33073 | High | MicrosoftWindows | Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate. | Oct 20, 2025 | KEV |
| CVE-2025-54253 | High | AdobeExperience Manager (AEM) Forms | Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution. | Oct 15, 2025 | KEV |
| CVE-2025-24990 | High | MicrosoftWindows | Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges. | Oct 14, 2025 | KEV |