IT
58.306 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2025-24045 HIGH 8.1 microsoft windows_server_2012 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. 1.3% —
CVE-2024-1654 HIGH 7.2 papercut papercut_mf This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to explo 1.3% —
CVE-2022-45802 CRIT 9.8 apache streampark Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to A 1.3% —
CVE-2020-17056 MED 5.5 microsoft windows_10 Windows Network File System Information Disclosure Vulnerability 1.3% —
CVE-2020-17013 MED 5.5 microsoft windows_10 Win32k Information Disclosure Vulnerability 1.3% —
CVE-2020-17004 MED 5.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 1.3% —
CVE-2020-17000 MED 5.5 microsoft windows_10 Remote Desktop Protocol Client Information Disclosure Vulnerability 1.3% —
CVE-2020-16999 MED 5.5 microsoft windows_10 Windows WalletService Information Disclosure Vulnerability 1.3% —
CVE-2020-14386 MED 6.7 debian debian_linux A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity. 1.3% —
CVE-2020-0775 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Information Disclosu 1.3% —
CVE-2019-6650 CRIT 9.1 f5 big-ip_application_security_manager F5 BIG-IP ASM 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 may expose sensitive information and allow the system configuration to be modified when using non-default settings. 1.3% —
CVE-2019-1294 MED 4.6 microsoft windows_10 A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'. 1.3% —
CVE-2018-25018 HIGH 7.8 rarlab unrar UnRAR 5.6.1.7 through 5.7.4 and 6.0.3 has an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from QuickOpen::ReadNext. 1.3% —
CVE-2018-13371 HIGH 8.8 fortinet fortios An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via connecting to the ZebOS component. 1.3% —
CVE-2016-3300 HIGH 7.8 microsoft windows_8.1 The Netlogon service in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 improperly establishes secure communications channels, which allows local users to gain privileges by leveraging access to a domain-joined machine, aka "Netlogon 1.3% —
CVE-2012-0331 HIGH 7.5 cisco telepresence_system_software Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP packet, as demonstrated by a SIP INVITE message from a Tandberg device, aka Bug ID CSCtq73319. 1.3% —
CVE-2021-43030 LOW 3.3 adobe premiere_rush Adobe Premiere Rush versions 1.5.16 (and earlier) allows access to an uninitialized pointer vulnerability that allows remote attackers to disclose arbitrary data on affected installations. User interaction is required to exploit this vulnerability in that the 1.3% —
CVE-2020-5883 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, when a virtual server is configured with HTTP explicit proxy and has an attached HTTP_PROXY_REQUEST iRule, POST requests sent to the virtual server cause an xdata memory leak. 1.3% —
CVE-2020-5881 HIGH 7.5 f5 big-ip_access_policy_manager On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when the BIG-IP Virtual Edition (VE) is configured with VLAN groups and there are devices configured with OSPF connected to it, the Network Device Abstraction Layer (NDAL) Interfaces can lock u 1.3% —
CVE-2020-5877 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, malformed input to the DATAGRAM::tcp iRules command within a FLOW_INIT event may lead to a denial of service. 1.3% —
CVE-2020-5875 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.0.1 and 14.1.0-14.1.2.3, under certain conditions, the Traffic Management Microkernel (TMM) may generate a core file and restart while processing SSL traffic with an HTTP/2 full proxy. 1.3% —
CVE-2020-5874 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP APM 15.0.0-15.0.1.2, 14.1.0-14.1.2.3, and 14.0.0-14.0.1, in certain circumstances, an attacker sending specifically crafted requests to a BIG-IP APM virtual server may cause a disruption of service provided by the Traffic Management Microkernel(TMM). 1.3% —
CVE-2020-5872 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.2.3, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.4.1, when processing TLS traffic with hardware cryptographic acceleration enabled on platforms with Intel QAT hardware, the Traffic Management Microkernel (TMM) may stop responding and 1.3% —
CVE-2019-6629 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts 1.3% —
CVE-2019-0075 HIGH 7.5 juniper junos A vulnerability in the srxpfe process on Protocol Independent Multicast (PIM) enabled SRX series devices may lead to crash of the srxpfe process and an FPC reboot while processing (PIM) messages. Sustained receipt of these packets may lead to an extended denia 1.3% —