58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2001-0056 | HIGH 7.5 | cisco broadband_operating_system The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection. | 1.4% | — |
| CVE-1999-0415 | HIGH 7.5 | cisco cisco_7xx_routers The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration. | 1.4% | — |
| CVE-2024-38167 | MED 6.5 | microsoft .net .NET and Visual Studio Information Disclosure Vulnerability | 1.4% | — |
| CVE-2024-23320 | HIGH 8.8 | apache dolphinscheduler Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we | 1.4% | — |
| CVE-2022-45347 | CRIT 9.8 | apache shardingsphere Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client. This | 1.4% | — |
| CVE-2021-39064 | HIGH 7.5 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Admin console. IBM X-Force ID: 214957. | 1.4% | — |
| CVE-2020-3808 | MED 5.9 | adobe creative_cloud Creative Cloud Desktop Application versions 5.0 and earlier have a time-of-check to time-of-use (toctou) race condition vulnerability. Successful exploitation could lead to arbitrary file deletion. | 1.4% | — |
| CVE-2020-17045 | MED 5.5 | microsoft windows_10 Windows KernelStream Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-17036 | MED 5.5 | microsoft windows_10 Windows Function Discovery SSDP Provider Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-17030 | MED 5.5 | microsoft windows_10 Windows MSCTF Server Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-17029 | MED 5.5 | microsoft windows_10 Windows Canonical Display Driver Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-1640 | HIGH 7.5 | juniper junos An improper use of a validation framework when processing incoming genuine BGP packets within Juniper Networks RPD (routing protocols process) daemon allows an attacker to crash RPD thereby causing a Denial of Service (DoS) condition. This framework requires t | 1.4% | — |
| CVE-2020-0874 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'. T | 1.4% | — |
| CVE-2018-4375 | HIGH 8.8 | apple icloud Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8. | 1.4% | — |
| CVE-2011-3297 | HIGH 7.8 | cisco catalyst_6500 Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authentication configurations are used, allows remote attackers to cause a denial of service (module crash) by making many | 1.4% | — |
| CVE-2009-4923 | HIGH 7.8 | cisco asa_5580 Unspecified vulnerability in the DTLS implementation on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (traceback) via TLS fragments, aka Bug ID CSCso53162. | 1.4% | — |
| CVE-2009-4920 | HIGH 7.8 | cisco asa_5580 Unspecified vulnerability in CTM on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software 8.1(2) allows remote attackers to cause a denial of service (watchdog traceback) via a large amount of small-packet data, aka Bug ID CSCsu11412. | 1.4% | — |
| CVE-2009-4918 | HIGH 7.8 | cisco asa_5580 Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remote attackers to cause a denial of service (IKE process hang) via malformed NAT-T packets, aka Bug ID CSCsr74439. | 1.4% | — |
| CVE-2009-4917 | HIGH 7.8 | cisco asa_5580 Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device reload) via a high volume of SIP traffic, aka Bug ID CSCsr65901. | 1.4% | — |
| CVE-2002-1557 | MED 5.0 | cisco optical_networking_systems_software Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset to TCC, TCC+, TCCi or XTC) via a malformed HTTP request that does not contain a leading / (slash) character. | 1.4% | — |
| CVE-2002-1556 | MED 5.0 | cisco optical_networking_systems_software Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset) via an HTTP request to the TCC, TCC+ or XTC, in which the request contains an invalid CORBA Interoperable Object Reference (IOR). | 1.4% | — |
| CVE-2022-30166 | HIGH 7.8 | microsoft windows_10 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2022-27491 | MED 6.8 | fortinet fortios A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.001 through 6.121, 5.001 through 5.258 and before 4.086 allows a remote and unauthenticated attacker to trigger | 1.4% | — |
| CVE-2020-3446 | CRIT 9.8 | cisco csp_5228-w_firmware A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for Cisco ENCS 5400-W Series and CSP 5000-W Series appliances could allow an unauthenticated, remote attacker to lo | 1.4% | — |
| CVE-2020-13998 | MED 5.3 | citrix xenapp Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vulnerability only affects products that are | 1.4% | — |