58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-23400 | HIGH 7.2 | microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2022-42466 | MED 6.1 | apache isis Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this w | 1.3% | — |
| CVE-2016-1322 | HIGH 7.5 | cisco spark The REST interface in Cisco Spark 2015-07-04 allows remote attackers to bypass intended access restrictions and create arbitrary user accounts via unspecified web requests, aka Bug ID CSCuv72584. | 1.3% | — |
| CVE-2016-1299 | MED 5.3 | cisco 300_series_managed_switch_firmware The web-management GUI implementation on Cisco Small Business SG300 devices 1.4.1.x allows remote attackers to cause a denial of service (HTTPS outage) via crafted HTTPS requests, aka Bug ID CSCuw87174. | 1.3% | — |
| CVE-2011-2731 | MED 5.1 | vmware springsource_spring_security Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread. | 1.3% | — |
| CVE-2025-29828 | HIGH 8.1 | microsoft windows_11_22h2 Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2024-31864 | CRIT 9.8 | apache zeppelin Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver. This issue affects Apache Zeppelin: before 0.11.1. U | 1.3% | — |
| CVE-2020-1331 | MED 5.4 | microsoft system_center_operations_manager A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnerability'. | 1.3% | — |
| CVE-2019-9962 | HIGH 7.8 | xnview xnview_mp XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to VCRUNTIME140!memcpy. | 1.3% | — |
| CVE-2019-1860 | MED 5.9 | cisco unified_intelligence_center A vulnerability in the dashboard gadget rendering of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to obtain or manipulate sensitive information between a user’s browser and Cisco Unified Intelligence Center. The vulne | 1.3% | — |
| CVE-2018-0195 | HIGH 8.8 | cisco ios_xe A vulnerability in the Cisco IOS XE Software REST API could allow an authenticated, remote attacker to bypass API authorization checks and use the API to perform privileged actions on an affected device. The vulnerability is due to insufficient authorization c | 1.3% | — |
| CVE-2025-23196 | HIGH 8.8 | apache ambari A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability arises when defining alert scripts, where the script filename field is executed usin | 1.3% | — |
| CVE-2021-40742 | MED 5.5 | adobe audition Adobe Audition version 14.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of | 1.3% | — |
| CVE-2021-40737 | MED 5.5 | adobe audition Adobe Audition version 14.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of | 1.3% | — |
| CVE-2026-42835 | HIGH 8.1 | microsoft teams Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2025-21342 | HIGH 8.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2021-29687 | MED 5.3 | ibm security_identity_manager IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 200018 | 1.3% | — |
| CVE-2020-35112 | HIGH 8.8 | mozilla firefox If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable w | 1.3% | — |
| CVE-2017-4931 | HIGH 7.8 | vmware airwatch VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add malicious data to an enrolled device's log files. Successful exploitation of this issue could result in an unsuspecting AWC user opening a CSV | 1.3% | — |
| CVE-2016-1270 | HIGH 7.5 | juniper junos The rpd daemon in Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D40, 13.3 before 13.3R6, 14.1 before 14.1R4, and 14.2 befo | 1.3% | — |
| CVE-2013-1155 | HIGH 7.8 | cisco firewall_services_module_software The auth-proxy functionality in Cisco Firewall Services Module (FWSM) software 3.1 and 3.2 before 3.2(20.1), 4.0 before 4.0(15.2), and 4.1 before 4.1(5.1) allows remote attackers to cause a denial of service (device reload) via a crafted URL, aka Bug ID CSCtg0 | 1.3% | — |
| CVE-2005-2280 | MED 5.0 | cisco security_agent Cisco Security Agent (CSA) 4.5 allows remote attackers to cause a denial of service (system crash) via a crafted IP packet. | 1.3% | — |
| CVE-2005-2243 | MED 5.0 | cisco call_manager Memory leak in inetinfo.exe in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1, when Multi Level Admin (MLA) is enabled, allows remote attackers to cause a denial of service (memory consumption) | 1.3% | — |
| CVE-2005-2241 | MED 5.0 | cisco call_manager Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote attack | 1.3% | — |
| CVE-2026-62878 | CRIT 9.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. | 1.3% | — |