58.352 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.352 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-12044 | HIGH 7.5 | citrix netscaler_application_delivery_controller_firmware A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x b | 1.5% | — |
| CVE-2018-0256 | MED 5.8 | cisco asr_5000_series_software A vulnerability in the peer-to-peer message processing functionality of Cisco Packet Data Network Gateway could allow an unauthenticated, remote attacker to cause the Session Manager (SESSMGR) process on an affected device to restart, resulting in a denial of | 1.5% | — |
| CVE-2017-5094 | MED 6.5 | debian debian_linux Type confusion in extensions JavaScript bindings in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to potentially maliciously modify objects via a crafted HTML page. | 1.5% | — |
| CVE-2007-2229 | HIGH 7.2 | microsoft windows_vista Microsoft Windows Vista uses insecure default permissions for unspecified "local user information data stores" in the registry and the file system, which allows local users to obtain sensitive information such as administrative passwords, aka "Permissive User | 1.5% | — |
| CVE-2005-0612 | HIGH 7.5 | cisco ipvc-3510-mcu Cisco IP/VC Videoconferencing System 3510, 3520, 3525 and 3530 contain hard-coded default SNMP community strings, which allows remote attackers to gain access, cause a denial of service, and modify configuration. | 1.5% | — |
| CVE-2023-21762 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 1.6% | — |
| CVE-2021-41024 | HIGH 7.5 | fortinet fortios A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the server v | 1.6% | — |
| CVE-2019-1370 | MED 5.5 | microsoft open_enclave_software_development_kit An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. | 1.6% | — |
| CVE-2017-3839 | MED 4.3 | cisco secure_access_control_system An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: | 1.6% | — |
| CVE-2014-3262 | MED 4.3 | cisco ios The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.3(3)S and earlier and IOS XE does not properly validate parameters in ITR control messages, which allows remote attackers to cause a denial of service (CEF outage and packet drops) via ma | 1.6% | — |
| CVE-2013-2900 | HIGH 7.5 | debian debian_linux The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not properly handle pathname components composed entirely of . (dot) and whitespace characters, which allows remote attackers to conduct director | 1.6% | — |
| CVE-2024-43622 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-43621 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-43620 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2023-42663 | MED 6.5 | apache airflow Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs. Users of Apache Airflow are advised to upgrade to version 2.7.2 or newe | 1.6% | — |
| CVE-2021-39235 | MED 6.5 | apache ozone In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block. | 1.6% | — |
| CVE-2021-26114 | CRIT 9.8 | fortinet fortiwan Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | 1.6% | — |
| CVE-2018-0292 | HIGH 8.8 | cisco nx-os A vulnerability in the Internet Group Management Protocol (IGMP) Snooping feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an | 1.6% | — |
| CVE-2017-5095 | HIGH 8.8 | debian debian_linux Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit stack corruption via a crafted PDF file. | 1.6% | — |
| CVE-2010-2830 | HIGH 7.1 | cisco ios The IGMPv3 implementation in Cisco IOS 12.2, 12.3, 12.4, and 15.0 and IOS XE 2.5.x before 2.5.2, when PIM is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed IGMP packet, aka Bug ID CSCte14603. | 1.6% | — |
| CVE-1999-0656 | MED 5.0 | linux linux_kernel The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names. | 1.6% | — |
| CVE-2026-27908 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally. | 1.6% | — |
| CVE-2021-41378 | HIGH 7.8 | microsoft windows_10 Windows NTFS Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2019-5007 | HIGH 7.1 | foxitsoftware foxit_reader An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is an Out-of-Bounds Read Information Disclosure and crash due to a NULL pointer dereference when reading TIFF data during TIFF parsing. | 1.6% | — |
| CVE-2026-24302 | HIGH 8.6 | microsoft azure_arc Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | 1.6% | — |