58.015 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.015 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-10855 | HIGH 7.8 | fujitsu fence-explorer Untrusted search path vulnerability in FENCE-Explorer for Windows V8.4.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 1.1% | — |
| CVE-2017-10851 | HIGH 7.8 | fujixerox contentsbridge_utility Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 1.1% | — |
| CVE-2026-20967 | HIGH 8.8 | microsoft system_center_operations_manager Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2022-21846 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2020-7858 | MED 6.8 | cdnetworks aquanplayer There is a directory traversing vulnerability in the download page url of AquaNPlayer 2.0.0.92. The IP of the download page url is localhost and an attacker can traverse directories using "dot dot" sequences(../../) to view host file on the system. This vulner | 1.1% | — |
| CVE-2020-5427 | HIGH 7.2 | vmware spring_cloud_data_flow In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution. | 1.1% | — |
| CVE-2020-1684 | HIGH 7.5 | juniper junos On Juniper Networks SRX Series configured with application identification inspection enabled, receipt of specific HTTP traffic can cause high CPU load utilization, which could lead to traffic interruption. Application identification is enabled by default and i | 1.1% | — |
| CVE-2019-6655 | MED 5.3 | f5 big-ip_access_policy_manager On versions 13.0.0-13.1.0.1, 12.1.0-12.1.4.1, 11.6.1-11.6.4, and 11.5.1-11.5.9, BIG-IP platforms where AVR, ASM, APM, PEM, AFM, and/or AAM is provisioned may leak sensitive data. | 1.1% | — |
| CVE-2018-0116 | HIGH 7.2 | cisco mobility_services_engine A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to be authorized as a subscriber without providing a valid password; however, the attacker must provide a valid username. The vulnerabilit | 1.1% | — |
| CVE-2017-6658 | HIGH 7.5 | cisco sourcefire_snort Cisco Sourcefire Snort 3.0 before build 233 has a Buffer Overread related to use of a decoder array. The size was off by one making it possible to read past the end of the array with an ether type of 0xFFFF. Increasing the array size solves this problem. | 1.1% | — |
| CVE-2017-6657 | HIGH 7.5 | cisco snort\+\+ Cisco Sourcefire Snort 3.0 before build 233 mishandles Ether Type Validation. Since valid ether type and IP protocol numbers do not overlap, Snort++ stores all protocol decoders in a single array. That makes it possible to craft packets that have IP protocol n | 1.1% | — |
| CVE-2013-1121 | MED 5.4 | cisco nx-os The regex engine in the BGP implementation in Cisco NX-OS, when a complex regular expression is configured for inbound routes, allows remote attackers to cause a denial of service (device reload) via a crafted AS path set, aka Bug ID CSCuf49554. | 1.1% | — |
| CVE-2011-2561 | HIGH 7.1 | cisco unified_communications_manager The SIP process in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(5b)su4 and 8.x before 8.0(1) does not properly handle SDP data within a SIP call in certain situations related to use of the g729ar8 codec for a Media Termi | 1.1% | — |
| CVE-2010-2981 | HIGH 7.1 | cisco unified_wireless_network_solution_software Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to cause a denial of service (device crash) by pinging a virtual interface, aka Bug ID CSCte55370. | 1.1% | — |
| CVE-2005-1837 | HIGH 7.5 | fortinet fortinet_firewall Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges. | 1.1% | — |
| CVE-1999-0230 | MED 5.0 | cisco ios Buffer overflow in Cisco 7xx routers through the telnet service. | 1.1% | — |
| CVE-2024-26240 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2024-24989 | HIGH 7.5 | f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer t | 1.1% | — |
| CVE-2023-46120 | MED 4.9 | vmware rabbitmq_java_client The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects. Attackers could send a very large Message causing a memory overflow and trigge | 1.1% | — |
| CVE-2020-3312 | HIGH 7.5 | cisco secure_firewall_management_center A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data on an affected device. The vulnerability is due to insuf | 1.1% | — |
| CVE-2018-18281 | HIGH 7.8 | canonical ubuntu_linux Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(), a stale TLB entry can remain for a short | 1.1% | — |
| CVE-2016-1386 | HIGH 7.5 | cisco application_policy_infrastructure_controller_enterprise_module The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) allows remote attackers to spoof administrative notifications via crafted attribute-value pairs, aka Bug ID CSCux15521. | 1.1% | — |
| CVE-2016-1373 | HIGH 8.6 | cisco finesse The gadgets-integration API in Cisco Finesse 8.5(1) through 8.5(5), 8.6(1), 9.0(1), 9.0(2), 9.1(1), 9.1(1)SU1, 9.1(1)SU1.1, 9.1(1)ES1 through 9.1(1)ES5, 10.0(1), 10.0(1)SU1, 10.0(1)SU1.1, 10.5(1), 10.5(1)ES1 through 10.5(1)ES4, 10.5(1)SU1, 10.5(1)SU1.1, 10.5(1 | 1.1% | — |
| CVE-2016-1342 | MED 5.3 | cisco secure_firewall_management_center The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-version information by reading help files, aka Bug ID CSCuy36654. | 1.1% | — |
| CVE-2013-5540 | MED 6.8 | cisco identity_services_engine The file-upload feature in Cisco Identity Services Engine (ISE) allows remote authenticated users to cause a denial of service (disk consumption and administration-interface outage) by uploading many files, aka Bug ID CSCui67519. | 1.1% | — |