IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2021-23015 HIGH 7.2 f5 big-ip_access_policy_manager On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an authenticated user assigned the 'Administrator' role may be able to bypass Appliance Mode restrictions utilizing u 1.3% —
CVE-2005-0921 MED 4.6 microsoft outlook_connector Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy. 1.3% —
CVE-2024-39563 HIGH 7.3 juniper junos_space A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance, leading to remote command execution by the 1.3% —
CVE-2024-29066 HIGH 7.2 microsoft windows_server_2008 Windows Distributed File System (DFS) Remote Code Execution Vulnerability 1.3% —
CVE-2024-28746 HIGH 8.1 apache airflow Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.  Users of Apache Airf 1.3% —
CVE-2023-47265 MED 5.4 apache airflow Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript in the parameter description field of the DAG. This Javascript can be executed on the client side of any of th 1.3% —
CVE-2022-37956 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.3% —
CVE-2022-22744 HIGH 8.8 mozilla firefox The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windows. Other operating s 1.3% —
CVE-2021-20427 HIGH 7.5 ibm security_guardium IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314. 1.3% —
CVE-2018-5500 MED 5.9 f5 big-ip_access_policy_manager On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCTCP) connection established leaks a small amount of memory. Virtual server using TCP profile with Multipath TCP (MCTCP) feature enabled will be affected by this 1.3% —
CVE-2018-15330 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, when a virtual server using the inflate functionality to process a gzip bomb as a payload, the BIG-IP system will experience a fatal error and may cause the Traffic Management Microkernel (TMM) to 1.3% —
CVE-2018-15318 HIGH 7.5 f5 big-ip_access_policy_manager In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives an abort signal while the initial flow is not the primary flow, the initial flow will remain after the closing procedure is complete. TMM may restart and produc 1.3% —
CVE-2017-8824 HIGH 7.8 linux linux_kernel The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state. 1.3% —
CVE-2010-0484 MED 6.8 microsoft windows_2000 The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 "do not properly validate changes in certain kernel objects," which allows local users to execute arbi 1.3% —
CVE-2023-49735 HIGH 7.5 apache tiles ** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing user-controlled data 1.3% —
CVE-2023-34060 CRIT 9.8 vmware cloud_director VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network a 1.3% —
CVE-2022-3564 MED 5.5 debian debian_linux A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended 1.3% —
CVE-2014-3402 MED 5.0 cisco intrusion_prevention_system The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote attackers to cause a denial of service ( 1.3% —
CVE-2011-0671 HIGH 8.4 microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain 1.3% —
CVE-2009-1922 MED 6.9 microsoft windows_2000 The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain pr 1.3% —
CVE-2026-63516 MED 6.5 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 1.3% —
CVE-2025-53793 HIGH 7.5 microsoft azure_stack_hub Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network. 1.3% —
CVE-2023-29373 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.3% —
CVE-2023-29372 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.3% —
CVE-2023-29362 HIGH 8.8 microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability 1.3% —