57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-44729 | HIGH 7.1 | apache xml_graphics_batik Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource | 0.9% | — |
| CVE-2021-29723 | HIGH 7.5 | ibm sterling_external_authentication_server IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-ForceID: 201100. | 0.9% | — |
| CVE-2021-29722 | HIGH 7.5 | ibm sterling_external_authentication_server IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201095. | 0.9% | — |
| CVE-2021-29488 | MED 4.3 | sabnzbd sabnzbd SABnzbd is an open source binary newsreader. A vulnerability was discovered in SABnzbd that could trick the `filesystem.renamer()` function into writing downloaded files outside the configured Download Folder via malicious PAR2 files. A patch was released as p | 0.9% | — |
| CVE-2021-23053 | MED 5.3 | f5 big-ip_advanced_web_application_firewall On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP Advanced WAF or BIG-IP ASM is enabled on a virtual server and the virtual server is under brute force attack, the MySQL datab | 0.9% | — |
| CVE-2020-15523 | HIGH 7.8 | netapp snapcenter In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid | 0.9% | — |
| CVE-2020-1393 | HIGH 7.8 | microsoft visual_studio An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka 'Windows Diagnostics Hub Elevation of Privilege Vulnerability'. Th | 0.9% | — |
| CVE-2020-1336 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenti | 0.9% | — |
| CVE-2016-4931 | MED 6.5 | juniper junos_space XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service. | 0.9% | — |
| CVE-2026-69716 | HIGH 8.8 | microsoft sharepoint_server Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2025-20358 | CRIT 9.4 | cisco unified_contact_center_express A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative permissions pertaining to script creation and execution. This vuln | 0.9% | — |
| CVE-2024-26174 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 0.9% | — |
| CVE-2022-29149 | HIGH 7.8 | microsoft azure_automation_state_configuration Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2022-23022 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.1.x before 16.1.2, when an HTTP profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are | 0.9% | — |
| CVE-2022-23021 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.1.x before 16.1.2, when any of the following configurations are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate: HTTP redirect rule in an LTM policy, BIG-IP APM Access Pr | 0.9% | — |
| CVE-2022-23019 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can caus | 0.9% | — |
| CVE-2022-23018 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager On BIG-IP AFM version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and 13.1.x beginning in 13.1.3.4, when a virtual server is configured with both HTTP protocol security and HTTP Proxy Connect profiles, undisclosed requests can cause t | 0.9% | — |
| CVE-2022-23017 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when a virtual server is configured with a DNS profile with the Rapid Response Mode setting enabled and is configured on a BIG-IP system, undisclo | 0.9% | — |
| CVE-2022-23016 | HIGH 7.5 | f5 big-ip_access_policy_manager On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP SSL Forward Proxy with TLS 1.3 is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have | 0.9% | — |
| CVE-2022-23012 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP versions 15.1.x before 15.1.4.1 and 14.1.x before 14.1.4.5, when the HTTP/2 profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached En | 0.9% | — |
| CVE-2022-22198 | HIGH 7.5 | juniper junos An Access of Uninitialized Pointer vulnerability in the SIP ALG of Juniper Networks Junos OS allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). Continued receipt of these specific packets will cause a sustained Denial of Servi | 0.9% | — |
| CVE-2021-1416 | MED 6.5 | cisco identity_services_engine Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information. These vulnerabilities are due to improper enforcement of administrator privilege levels for sens | 0.9% | — |
| CVE-2020-27124 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the SSL/TLS handler of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause the affected device to reload unexpectedly, leading to a denial of service (DoS) condition. The vulnerabil | 0.9% | — |
| CVE-2020-1547 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted applicat | 0.9% | — |
| CVE-2026-73025 | CRIT 9.8 | microsoft windows_10_1607 Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network. | 0.9% | — |