58.285 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.285 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-35642 | MED 6.5 | microsoft windows_10_1507 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.3% | — |
| CVE-2022-22002 | MED 5.5 | microsoft windows_10 Windows User Account Profile Picture Denial of Service Vulnerability | 1.3% | — |
| CVE-2020-3370 | MED 5.8 | cisco email_security_appliance A vulnerability in URL filtering of Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to bypass URL filtering on an affected device. The vulnerability is due to insufficient input validation. An attacker could ex | 1.3% | — |
| CVE-2019-0064 | HIGH 7.5 | juniper junos On SRX5000 Series devices, if 'set security zones security-zone <zone> tcp-rst' is configured, the flowd process may crash when a specific TCP packet is received by the device and triggers a new session. The process restarts automatically. However, receipt of | 1.3% | — |
| CVE-2019-0063 | MED 6.5 | juniper junos When an MX Series Broadband Remote Access Server (BRAS) is configured as a Broadband Network Gateway (BNG) with DHCPv6 enabled, jdhcpd might crash when receiving a specific crafted DHCP response message on a subscriber interface. The daemon automatically resta | 1.3% | — |
| CVE-2019-0050 | HIGH 7.5 | juniper junos Under certain heavy traffic conditions srxpfe process can crash and result in a denial of service condition for the SRX1500 device. Repeated crashes of the srxpfe can result in an extended denial of service condition. The SRX device may fail to forward traffic | 1.3% | — |
| CVE-2016-6419 | HIGH 7.5 | cisco secure_firewall_management_center SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485. | 1.3% | — |
| CVE-2010-4202 | CRIT 9.8 | google chrome Multiple integer overflows in Google Chrome before 7.0.517.44 on Linux allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted font. | 1.3% | — |
| CVE-2010-2977 | HIGH 10.0 | cisco unified_wireless_network_solution_software Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 does not properly implement TLS and SSL, which has unspecified impact and remote attack vectors, aka Bug ID CSCtd01611. | 1.3% | — |
| CVE-2025-29967 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2023-51389 | CRIT 9.8 | apache hertzbeat Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security configuration is used, resulting in a YAML deserialization vulnerability. Version 1.4.1 fixes this vulnerability. | 1.3% | — |
| CVE-2021-39072 | MED 5.9 | ibm security_guardium IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the mid | 1.3% | — |
| CVE-2020-3998 | MED 6.5 | vmware horizon_client VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious attacker with local privileges on the machine where Horizon Client for Windows is installed may be able to retrieve hashed credentials if the c | 1.3% | — |
| CVE-2017-9491 | MED 5.3 | cisco dpc3939_firmware The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST); Cisco DPC394 | 1.3% | — |
| CVE-2006-0023 | MED 4.3 | microsoft windows_xp Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Se | 1.3% | — |
| CVE-2022-33869 | HIGH 8.8 | fortinet fortiwan An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 through 4.5.9 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to e | 1.3% | — |
| CVE-2022-2585 | MED 5.3 | canonical ubuntu_linux It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free. | 1.3% | — |
| CVE-2021-1353 | MED 5.8 | cisco staros A vulnerability in the IPv4 protocol handling of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory leak that occurs during packet processing. An | 1.3% | — |
| CVE-2021-1272 | HIGH 8.8 | cisco data_center_network_manager A vulnerability in the session validation feature of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. This vulnerabi | 1.3% | — |
| CVE-2020-9606 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution . | 1.3% | — |
| CVE-2020-4761 | MED 5.3 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information coul | 1.3% | — |
| CVE-2020-4600 | MED 5.3 | ibm security_guardium_insights IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 184832. | 1.3% | — |
| CVE-2020-4599 | MED 5.3 | ibm security_guardium_insights IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 184824. | 1.3% | — |
| CVE-2020-1634 | HIGH 7.5 | juniper junos On High-End SRX Series devices, in specific configurations and when specific networking events or operator actions occur, an SPC receiving genuine multicast traffic may core. Subsequently, all FPCs in a chassis may reset causing a Denial of Service. This issue | 1.3% | — |
| CVE-2018-0436 | HIGH 8.7 | cisco webex_teams A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The vulnerability exists because the affected software performs insufficien | 1.3% | — |