57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.808 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-1192 | MED 6.5 | linux linux_kernel A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses i | 1.1% | — |
| CVE-2018-0831 | HIGH 7.8 | microsoft windows_10 The Windows kernel in Windows 10 versions 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Kernel Elevation of Privilege Vulnerabilit | 1.1% | — |
| CVE-2017-7661 | HIGH 8.8 | apache cxf_fediz Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3, Jetty 8 and Jetty 9 plugins in Apache CXF Fediz prio | 1.1% | — |
| CVE-2017-5573 | MED 4.9 | citrix xenserver An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can cancel tasks of other administrators. | 1.1% | — |
| CVE-2017-5572 | MED 6.5 | citrix xenserver An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can corrupt the host database. | 1.1% | — |
| CVE-2016-6395 | MED 5.4 | cisco firesight_system_software Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, | 1.1% | — |
| CVE-2026-47359 | HIGH 8.8 | apache cloudstack Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API (available since 4.20.0.0) and updateBackupRepository API (introduced in 4.2 | 1.1% | — |
| CVE-2023-4593 | MED 6.5 | seattlelab slmail Path traversal vulnerability whose exploitation could allow an authenticated remote user to bypass SecurityManager's intended restrictions and list a parent directory via any filename, such as a multiple ..%2F value affecting the 'dodoc' parameter in the /Mail | 1.1% | — |
| CVE-2023-35701 | MED 6.6 | apache hive Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and it can potentially lead to arbitrary code execution on the machine/endpoint that the JDBC driver (client) is r | 1.1% | — |
| CVE-2023-25921 | HIGH 8.5 | ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247620. | 1.1% | — |
| CVE-2023-24893 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-21699 | MED 5.3 | microsoft windows_10 Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability | 1.1% | — |
| CVE-2023-21679 | HIGH 8.1 | microsoft windows_10_1607 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-21555 | HIGH 8.1 | microsoft windows_10_1607 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-21546 | HIGH 8.1 | microsoft windows_10_1607 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-45801 | MED 5.4 | apache streampark Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that construct LDAP statements based on user input. When an application fails to properly sanitize user input, it's possibl | 1.1% | — |
| CVE-2022-37392 | MED 5.3 | apache traffic_server Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. | 1.1% | — |
| CVE-2022-20919 | HIGH 8.6 | cisco ios_xe A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting | 1.1% | — |
| CVE-2020-5936 | HIGH 7.5 | f5 big-ip_local_traffic_manager On BIG-IP LTM 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.1, the Traffic Management Microkernel (TMM) process may consume excessive resources when processing SSL traffic and client authentication are enabled on the client SSL profile. | 1.1% | — |
| CVE-2018-4412 | HIGH 7.8 | apple icloud A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7. | 1.1% | — |
| CVE-2017-12329 | MED 6.3 | cisco firepower_extensible_operating_system A vulnerability in the CLI of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command | 1.1% | — |
| CVE-2015-3290 | HIGH 7.2 | linux linux_kernel arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during nested NMI processing, which allows local users to gain privileges by triggering an NMI within a certain instruction window. | 1.1% | — |
| CVE-2022-45135 | CRIT 9.8 | apache cocoon Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue. | 1.1% | — |
| CVE-2022-39337 | HIGH 7.5 | apache hertzbeat Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat versions 1.20 and prior have a permission bypass vulnerability. System authentication can be bypassed and invoke | 1.1% | — |
| CVE-2021-24013 | HIGH 8.8 | fortinet fortimail Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and data via specifically crafted web requests. | 1.1% | — |