58.306 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-24045 | HIGH 8.1 | microsoft windows_server_2012 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2024-1654 | HIGH 7.2 | papercut papercut_mf This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to explo | 1.3% | — |
| CVE-2022-45802 | CRIT 9.8 | apache streampark Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to A | 1.3% | — |
| CVE-2020-17056 | MED 5.5 | microsoft windows_10 Windows Network File System Information Disclosure Vulnerability | 1.3% | — |
| CVE-2020-17013 | MED 5.5 | microsoft windows_10 Win32k Information Disclosure Vulnerability | 1.3% | — |
| CVE-2020-17004 | MED 5.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 1.3% | — |
| CVE-2020-17000 | MED 5.5 | microsoft windows_10 Remote Desktop Protocol Client Information Disclosure Vulnerability | 1.3% | — |
| CVE-2020-16999 | MED 5.5 | microsoft windows_10 Windows WalletService Information Disclosure Vulnerability | 1.3% | — |
| CVE-2020-14386 | MED 6.7 | debian debian_linux A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity. | 1.3% | — |
| CVE-2020-0775 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Information Disclosu | 1.3% | — |
| CVE-2019-6650 | CRIT 9.1 | f5 big-ip_application_security_manager F5 BIG-IP ASM 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 may expose sensitive information and allow the system configuration to be modified when using non-default settings. | 1.3% | — |
| CVE-2019-1294 | MED 4.6 | microsoft windows_10 A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'. | 1.3% | — |
| CVE-2018-25018 | HIGH 7.8 | rarlab unrar UnRAR 5.6.1.7 through 5.7.4 and 6.0.3 has an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from QuickOpen::ReadNext. | 1.3% | — |
| CVE-2018-13371 | HIGH 8.8 | fortinet fortios An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via connecting to the ZebOS component. | 1.3% | — |
| CVE-2016-3300 | HIGH 7.8 | microsoft windows_8.1 The Netlogon service in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 improperly establishes secure communications channels, which allows local users to gain privileges by leveraging access to a domain-joined machine, aka "Netlogon | 1.3% | — |
| CVE-2012-0331 | HIGH 7.5 | cisco telepresence_system_software Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP packet, as demonstrated by a SIP INVITE message from a Tandberg device, aka Bug ID CSCtq73319. | 1.3% | — |
| CVE-2021-43030 | LOW 3.3 | adobe premiere_rush Adobe Premiere Rush versions 1.5.16 (and earlier) allows access to an uninitialized pointer vulnerability that allows remote attackers to disclose arbitrary data on affected installations. User interaction is required to exploit this vulnerability in that the | 1.3% | — |
| CVE-2020-5883 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, when a virtual server is configured with HTTP explicit proxy and has an attached HTTP_PROXY_REQUEST iRule, POST requests sent to the virtual server cause an xdata memory leak. | 1.3% | — |
| CVE-2020-5881 | HIGH 7.5 | f5 big-ip_access_policy_manager On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when the BIG-IP Virtual Edition (VE) is configured with VLAN groups and there are devices configured with OSPF connected to it, the Network Device Abstraction Layer (NDAL) Interfaces can lock u | 1.3% | — |
| CVE-2020-5877 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, malformed input to the DATAGRAM::tcp iRules command within a FLOW_INIT event may lead to a denial of service. | 1.3% | — |
| CVE-2020-5875 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.0.1 and 14.1.0-14.1.2.3, under certain conditions, the Traffic Management Microkernel (TMM) may generate a core file and restart while processing SSL traffic with an HTTP/2 full proxy. | 1.3% | — |
| CVE-2020-5874 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP APM 15.0.0-15.0.1.2, 14.1.0-14.1.2.3, and 14.0.0-14.0.1, in certain circumstances, an attacker sending specifically crafted requests to a BIG-IP APM virtual server may cause a disruption of service provided by the Traffic Management Microkernel(TMM). | 1.3% | — |
| CVE-2020-5872 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.2.3, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.4.1, when processing TLS traffic with hardware cryptographic acceleration enabled on platforms with Intel QAT hardware, the Traffic Management Microkernel (TMM) may stop responding and | 1.3% | — |
| CVE-2019-6629 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts | 1.3% | — |
| CVE-2019-0075 | HIGH 7.5 | juniper junos A vulnerability in the srxpfe process on Protocol Independent Multicast (PIM) enabled SRX series devices may lead to crash of the srxpfe process and an FPC reboot while processing (PIM) messages. Sustained receipt of these packets may lead to an extended denia | 1.3% | — |