57.924 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.924 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-0633 | MED 6.8 | cisco unified_computing_system The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending crafted DHCP response packets on the local network, aka Bug ID | 1.0% | — |
| CVE-2025-62214 | MED 6.7 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally. | 1.0% | — |
| CVE-2023-36895 | HIGH 7.8 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-1829 | HIGH 7.8 | linux linux_kernel A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting | 1.0% | — |
| CVE-2020-1655 | MED 5.3 | juniper junos When a device running Juniper Networks Junos OS with MPC7, MPC8, or MPC9 line cards installed and the system is configured for inline IP reassembly, used by L2TP, MAP-E, GRE, and IPIP, the packet forwarding engine (PFE) will become disabled upon receipt of lar | 1.0% | — |
| CVE-2019-6592 | CRIT 9.1 | f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.0.1, TMM may restart and produce a core file when validating SSL certificates in client SSL or server SSL profiles. | 1.0% | — |
| CVE-2026-58529 | HIGH 7.1 | microsoft windows_11_26h1 Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-57991 | HIGH 7.4 | microsoft edge_chromium Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-20224 | HIGH 8.6 | cisco catalyst_sd-wan_manager A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials. | 1.0% | — |
| CVE-2022-20736 | MED 5.3 | cisco appdynamics_controller A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and the login page for an administrative console that they would not normally have aut | 1.0% | — |
| CVE-2021-34787 | MED 5.3 | cisco adaptive_security_appliance A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. | 1.0% | — |
| CVE-2019-1582 | HIGH 7.2 | paloaltonetworks pan-os Memory corruption in PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow an administrative user to cause arbitrary memory corruption by rekeying the current client interactive session. | 1.0% | — |
| CVE-2016-1477 | MED 6.5 | cisco connected_streaming_analytics Cisco Connected Streaming Analytics 1.1.1 allows remote authenticated users to discover a notification service password by reading administrative pages, aka Bug ID CSCuz92891. | 1.0% | — |
| CVE-2009-2861 | HIGH 7.3 | cisco aironet_ap1100 The Over-the-Air Provisioning (OTAP) functionality on Cisco Aironet Lightweight Access Point 1100 and 1200 devices does not properly implement access-point association, which allows remote attackers to spoof a controller and cause a denial of service (service | 1.0% | — |
| CVE-2007-6190 | LOW 3.5 | cisco unified_ip_phone The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones associated with the same CUCM server to eavesdrop on the physical environment via a CiscoIPPhoneExecute message con | 1.0% | — |
| CVE-2007-1258 | MED 6.1 | cisco catalyst_6000 Unspecified vulnerability in Cisco IOS 12.2SXA, SXB, SXD, and SXF; and the MSFC2, MSFC2a and MSFC3 running in Hybrid Mode on Cisco Catalyst 6000, 6500 and Cisco 7600 series systems; allows remote attackers on a local network segment to cause a denial of servic | 1.0% | — |
| CVE-2024-26181 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Denial of Service Vulnerability | 1.0% | — |
| CVE-2023-51656 | CRIT 9.8 | apache iotdb Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended to upgrade to version 1.2.2, which fixes the issue. | 1.0% | — |
| CVE-2023-30429 | CRIT 9.6 | apache pulsar Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. When a client connects to the Pulsar Function Worker via the Pulsar Proxy where the Pulsar Proxy uses mTLS authent | 1.0% | — |
| CVE-2021-24018 | MED 4.3 | fortinet fortios A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may allow an attacker located in the adjacent network to potentially execute arbitrary code via a specifically crafted firmware image. | 1.0% | — |
| CVE-2021-22914 | HIGH 7.5 | citrix cloud_connector Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an malicious actor to access a C | 1.0% | — |
| CVE-2020-1011 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows System Assessment Tool improperly handles file operations, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-0983, CVE-2020-1009, CVE-2020-1015 | 1.0% | — |
| CVE-2020-1009 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Microsoft Store Install Service handles file operations in protected locations, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-0983, CVE- | 1.0% | — |
| CVE-2019-6608 | MED 5.9 | f5 big-ip_access_policy_manager On BIG-IP 11.5.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, the snmpd daemon may leak memory on a multi-blade BIG-IP vCMP guest when processing authorized SNMP requests. | 1.0% | — |
| CVE-2011-4487 | MED 6.8 | cisco business_edition_3000 SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with s | 1.0% | — |