58.387 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.387 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-6159 | MED 5.9 | f5 big-ip_access_policy_manager F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service attack when the MPTCP option is enabled on a virtual server. Data plane is vulnerabl | 1.6% | — |
| CVE-2017-12363 | MED 5.3 | cisco webex_meetings_server A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on an affected system. The vulnerability is due to insufficient security settings on meetings. An attacker could exploit th | 1.6% | — |
| CVE-2017-12318 | HIGH 7.5 | cisco rf_gateway_1_firmware A vulnerability in the TCP state machine of Cisco RF Gateway 1 devices could allow an unauthenticated, remote attacker to prevent an affected device from delivering switched digital video (SDV) or video on demand (VoD) streams, resulting in a denial of service | 1.6% | — |
| CVE-2017-12245 | HIGH 8.6 | cisco secure_firewall_management_center A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause depletion of system memory, aka a Firepower Detection Engine SSL Decryption Memory Consumption Denial of Servic | 1.6% | — |
| CVE-2016-9205 | HIGH 7.5 | cisco ios_xr A vulnerability in the HTTP 2.0 request handling code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash, resulting in a denial of service (DoS) condition. More Information: CSC | 1.6% | — |
| CVE-2016-6469 | HIGH 7.5 | cisco web_security_appliance A vulnerability in HTTP URL parsing of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) vulnerability due to the proxy process unexpectedly restarting. More Information: CSC | 1.6% | — |
| CVE-2015-0773 | MED 5.5 | cisco firesight_system_software Cisco FireSIGHT System Software 5.3.1.3 and 6.0.0 allows remote authenticated users to delete an arbitrary user's dashboard via a modified VPN deletion request in a management session, aka Bug ID CSCut67078. | 1.6% | — |
| CVE-2010-1891 | MED 6.9 | microsoft windows_server_2003 The Client/Server Runtime Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2, when a Chinese, Japanese, or Korean locale is enabled, does not properly allocate memory for transactions, which allows local users | 1.6% | — |
| CVE-2026-61348 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 1.6% | — |
| CVE-2023-32083 | MED 6.5 | microsoft windows_server_2016 Microsoft Failover Cluster Information Disclosure Vulnerability | 1.6% | — |
| CVE-2023-28247 | HIGH 7.5 | microsoft windows_server_2012 Windows Network File System Information Disclosure Vulnerability | 1.6% | — |
| CVE-2023-24901 | HIGH 7.5 | microsoft windows_10_1507 Windows NFS Portmapper Information Disclosure Vulnerability | 1.6% | — |
| CVE-2018-6957 | MED 5.3 | vmware fusion VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and | 1.6% | — |
| CVE-2015-6308 | MED 4.0 | cisco nx-os Cisco NX-OS 6.0(2)U6(0.46) on N3K devices allows remote authenticated users to cause a denial of service (temporary SNMP outage) via an SNMP request for an OID that does not exist, aka Bug ID CSCuw36684. | 1.6% | — |
| CVE-2015-6300 | MED 4.0 | cisco secure_access_control_server Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users to cause a denial of service (SSH screen process crash) via crafted (1) CLI or (2) GUI commands, aka Bug ID CSCuw24694. | 1.6% | — |
| CVE-2015-4269 | MED 4.0 | cisco unified_communications_manager The Tomcat throttling feature in Cisco Unified Communications Manager 10.5(1.99995.9) allows remote authenticated users to cause a denial of service (management outage) by sending many requests, aka Bug ID CSCuu99709. | 1.6% | — |
| CVE-2012-3000 | HIGH 7.5 | f5 big-ip_access_policy_manager Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings.php in the (1) APM WebGUI in F5 BIG-IP LTM, GTM, ASM, Link Controller, PSM, APM, Edge Gateway, and Analytics and (2) AVR WebGUI in WebAccelerator and WOM 11.2.x before 11.2.0-HF3 and | 1.6% | — |
| CVE-2005-0601 | HIGH 7.5 | cisco application_and_content_networking_software Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, 5.1, or 5.2 use a default password when the setup dialog has not been run, which allows remote attackers to gain access. | 1.6% | — |
| CVE-2025-29827 | CRIT 9.9 | microsoft azure_automation Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. | 1.6% | — |
| CVE-2023-36415 | HIGH 8.8 | microsoft azure_identity_sdk Azure Identity SDK Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-41097 | MED 6.5 | microsoft windows_10 Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability | 1.6% | — |
| CVE-2020-1653 | HIGH 7.5 | juniper junos On Juniper Networks Junos OS devices, a stream of TCP packets sent to the Routing Engine (RE) may cause mbuf leak which can lead to Flexible PIC Concentrator (FPC) crash or the system to crash and restart (vmcore). This issue can be trigged by IPv4 or IPv6 and | 1.6% | — |
| CVE-2015-6266 | MED 5.0 | cisco identity_services_engine_software The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote attackers to obtain sensitive information from customized documents via a direct request, aka Bug ID CSCuo78045. | 1.6% | — |
| CVE-2014-0229 | MED 6.5 | apache hadoop Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated | 1.6% | — |
| CVE-2013-6943 | MED 5.0 | citrix netscaler_application_delivery_controller_firmware Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to conduct an LDAP injection attack via vectors related to SSH and Web management usernames. | 1.6% | — |