IT
58.165 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.165 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2025-50157 MED 5.7 microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. 1.2%
CVE-2024-20673 HIGH 7.8 microsoft excel Microsoft Office Remote Code Execution Vulnerability 1.2%
CVE-2023-46749 MED 6.5 apache shiro Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+, or ensure `blockSemicolon 1.2%
CVE-2023-28406 MED 4.3 f5 big-ip_access_policy_manager A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control wha 1.2%
CVE-2021-34703 MED 6.8 cisco ios A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and Cisco IOS XE Software could allow an attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability i 1.2%
CVE-2021-34699 HIGH 7.7 cisco ios A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to an improper interaction between the web UI and the CLI parser. A 1.2%
CVE-2014-8006 MED 4.3 cisco isb8320-e_high-definition_ip-only_dvr The Disaster Recovery (DRA) feature on the Cisco ISB8320-E High-Definition IP-Only DVR allows remote attackers to bypass authentication by establishing a TELNET session during a recovery boot, aka Bug ID CSCup85422. 1.2%
CVE-2013-3426 MED 5.0 cisco unified_ip_phone_9951 The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specifying a pathname in a file request, aka Bug ID CSCuh52810. 1.2%
CVE-2023-49736 MED 6.5 apache superset A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Superset.This issue affects Apache Superset: before 2.1.2, from 3.0.0 before 3.0.2. Users are recommended to upgr 1.2%
CVE-2023-21799 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.2%
CVE-2023-21798 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.2%
CVE-2023-21797 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.2%
CVE-2022-41617 HIGH 7.2 f5 big-ip_advanced_web_application_firewall In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is provisioned, an authenticated remote code execution vulnerability exists in the BIG-IP iControl REST interface 1.2%
CVE-2021-1614 MED 5.3 cisco sd-wan A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to gain access to information stored in MPLS buffer memory. This vulnerability is due to insufficient 1.2%
CVE-2021-1422 HIGH 7.7 cisco adaptive_security_appliance_software A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker or an unauthenticated attacker in a man-in-the-middle positi 1.2%
CVE-2013-1279 HIGH 7.2 microsoft windows_7 Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges 1.2%
CVE-2026-82008 CRIT 9.9 adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Explo 1.2%
CVE-2025-54812 MED 5.4 apache log4cxx Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not properly escaped when writing out to the HTML file. If untrusted data is used to retrieve the name of a logger, an attacker could theoretical 1.2%
CVE-2023-51518 CRIT 9.8 apache james Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Given a deserialisation gadjet, this could be leveraged as part of an exploit chain that could result in privileg 1.2%
CVE-2014-7286 HIGH 7.2 symantec deployment_solution Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local users to gain privileges via unspecified vectors. 1.2%
CVE-2013-3424 MED 6.8 cisco secure_access_control_system Cross-site request forgery (CSRF) vulnerability in Administration and View pages in Cisco Secure Access Control System (ACS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCud75177. 1.2%
CVE-2011-4007 MED 5.4 cisco ios Cisco IOS 15.0 and 15.1 and IOS XE 3.x do not properly handle the "set mpls experimental imposition" command, which allows remote attackers to cause a denial of service (device crash) via network traffic that triggers (1) fragmentation or (2) reassembly, aka B 1.2%
CVE-2011-2586 MED 5.4 cisco ios The HTTP client in Cisco IOS 12.4 and 15.0 allows user-assisted remote attackers to cause a denial of service (device crash) via a malformed HTTP response to a request for service installation, aka Bug ID CSCts12249. 1.2%
CVE-2005-2181 HIGH 7.5 cisco ip_phone_7940_firmware Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message. 1.2%
CVE-2005-0820 MED 5.0 Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web ser 1.2%