IT
57.918 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.918 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2020-7858 MED 6.8 cdnetworks aquanplayer There is a directory traversing vulnerability in the download page url of AquaNPlayer 2.0.0.92. The IP of the download page url is localhost and an attacker can traverse directories using "dot dot" sequences(../../) to view host file on the system. This vulner 1.1%
CVE-2020-5427 HIGH 7.2 vmware spring_cloud_data_flow In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution. 1.1%
CVE-2020-1684 HIGH 7.5 juniper junos On Juniper Networks SRX Series configured with application identification inspection enabled, receipt of specific HTTP traffic can cause high CPU load utilization, which could lead to traffic interruption. Application identification is enabled by default and i 1.1%
CVE-2019-6655 MED 5.3 f5 big-ip_access_policy_manager On versions 13.0.0-13.1.0.1, 12.1.0-12.1.4.1, 11.6.1-11.6.4, and 11.5.1-11.5.9, BIG-IP platforms where AVR, ASM, APM, PEM, AFM, and/or AAM is provisioned may leak sensitive data. 1.1%
CVE-2018-0116 HIGH 7.2 cisco mobility_services_engine A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to be authorized as a subscriber without providing a valid password; however, the attacker must provide a valid username. The vulnerabilit 1.1%
CVE-2017-6658 HIGH 7.5 cisco sourcefire_snort Cisco Sourcefire Snort 3.0 before build 233 has a Buffer Overread related to use of a decoder array. The size was off by one making it possible to read past the end of the array with an ether type of 0xFFFF. Increasing the array size solves this problem. 1.1%
CVE-2017-6657 HIGH 7.5 cisco snort\+\+ Cisco Sourcefire Snort 3.0 before build 233 mishandles Ether Type Validation. Since valid ether type and IP protocol numbers do not overlap, Snort++ stores all protocol decoders in a single array. That makes it possible to craft packets that have IP protocol n 1.1%
CVE-2013-1121 MED 5.4 cisco nx-os The regex engine in the BGP implementation in Cisco NX-OS, when a complex regular expression is configured for inbound routes, allows remote attackers to cause a denial of service (device reload) via a crafted AS path set, aka Bug ID CSCuf49554. 1.1%
CVE-2011-2561 HIGH 7.1 cisco unified_communications_manager The SIP process in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(5b)su4 and 8.x before 8.0(1) does not properly handle SDP data within a SIP call in certain situations related to use of the g729ar8 codec for a Media Termi 1.1%
CVE-2010-2981 HIGH 7.1 cisco unified_wireless_network_solution_software Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to cause a denial of service (device crash) by pinging a virtual interface, aka Bug ID CSCte55370. 1.1%
CVE-2005-1837 HIGH 7.5 fortinet fortinet_firewall Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges. 1.1%
CVE-1999-0230 MED 5.0 cisco ios Buffer overflow in Cisco 7xx routers through the telnet service. 1.1%
CVE-2026-78461 HIGH 7.4 microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. 1.1%
CVE-2026-70019 MED 6.5 microsoft windows_11_23h2 Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network. 1.1%
CVE-2026-32071 HIGH 7.5 microsoft windows_10_1607 Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. 1.1%
CVE-2025-20374 MED 4.9 cisco unified_contact_center_express A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory traversal and access arbitrary resources. This vulnerability is due to an insufficient input validation associated to specific UI feature 1.1%
CVE-2023-36639 HIGH 7.2 fortinet fortios A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiPA 1.1%
CVE-2022-34719 HIGH 7.8 microsoft windows_10 Windows Distributed File System (DFS) Elevation of Privilege Vulnerability 1.1%
CVE-2022-21897 HIGH 7.8 microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability 1.1%
CVE-2020-5864 HIGH 7.4 f5 nginx_controller In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default. 1.1%
CVE-2017-10887 HIGH 7.8 bookwalker book_walker Untrusted search path vulnerability in BOOK WALKER for Windows Ver.1.2.9 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. 1.1%
CVE-2017-10855 HIGH 7.8 fujitsu fence-explorer Untrusted search path vulnerability in FENCE-Explorer for Windows V8.4.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. 1.1%
CVE-2017-10851 HIGH 7.8 fujixerox contentsbridge_utility Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. 1.1%
CVE-2024-49065 MED 5.5 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 1.1%
CVE-2024-31869 MED 4.3 apache airflow Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via the "configuration" UI page when "non-sensitive-only" was set as "webserver.expose_config" configuration (The celery provide 1.1%