57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1561 | MED 5.4 | cisco secure_email_and_web_manager A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), could allow an authenticated, remote attacker to gain unauthorized access and modify the spam quarantine settings of anoth | 0.7% | — |
| CVE-2015-6932 | MED 5.8 | vmware vcenter_server VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0.7% | — |
| CVE-2008-5713 | MED 4.9 | linux linux_kernel The __qdisc_run function in net/sched/sch_generic.c in the Linux kernel before 2.6.25 on SMP machines allows local users to cause a denial of service (soft lockup) by sending a large amount of network traffic, as demonstrated by multiple simultaneous invocatio | 0.7% | — |
| CVE-2026-50505 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-50500 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-50340 | HIGH 8.5 | microsoft windows_11_24h2 Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-54090 | MED 6.3 | apache http_server A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue. | 0.7% | — |
| CVE-2024-49114 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-45217 | HIGH 8.1 | apache solr Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata. ConfigSets that | 0.7% | — |
| CVE-2024-42516 | HIGH 7.5 | apache http_server HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 b | 0.7% | — |
| CVE-2023-28295 | HIGH 7.8 | microsoft 365_apps Microsoft Publisher Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-28287 | HIGH 7.8 | microsoft 365_apps Microsoft Publisher Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-34167 | MED 5.4 | ibm cics_tx IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within | 0.7% | — |
| CVE-2022-34166 | MED 5.4 | ibm cics_tx IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust | 0.7% | — |
| CVE-2022-20868 | MED 4.7 | cisco asyncos A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker n | 0.7% | — |
| CVE-2021-44750 | MED 6.4 | f-secure client_security An arbitrary code execution vulnerability was found in the F-Secure Support Tool. A standard user can craft a special configuration file, which when run by administrator can execute any commands. | 0.7% | — |
| CVE-2019-1186 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticate | 0.7% | — |
| CVE-2019-1173 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally a | 0.7% | — |
| CVE-2019-0038 | MED 6.5 | juniper junos Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial of service (DoS) condition due to buffer space exhaustion. This issue only affects the SRX340 and SRX345 services gateways. No other product | 0.7% | — |
| CVE-2017-0650 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the Synaptics touchscreen driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Low because it first requires compromising a privileged process. Prod | 0.7% | — |
| CVE-2016-9775 | HIGH 7.8 | apache tomcat The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u7 on Debian whee | 0.7% | — |
| CVE-2016-6757 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in Qualcomm components including the camera driver and video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires co | 0.7% | — |
| CVE-2016-6756 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in Qualcomm components including the camera driver and video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires co | 0.7% | — |
| CVE-2009-2767 | HIGH 7.2 | linux kernel The init_posix_timers function in kernel/posix-timers.c in the Linux kernel before 2.6.31-rc6 allows local users to cause a denial of service (OOPS) or possibly gain privileges via a CLOCK_MONOTONIC_RAW clock_nanosleep call that triggers a NULL pointer derefer | 0.7% | — |
| CVE-2009-1156 | MED 5.7 | cisco adaptive_security_appliance_5500 Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series devices 8.0 before 8.0(4)25 and 8.1 before 8.1(2)15, when an SSL VPN or ASDM access is configured, allows remote attackers to cause a denial of service (device reload) via a craf | 0.7% | — |