58.458 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.458 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-1575 | HIGH 7.5 | cisco content_services_switch_11500 The Cisco Content Services Switch (CSS) 11500 with software 08.20.1.01 conveys authentication data through ClientCert-* headers but does not delete client-supplied ClientCert-* headers, which might allow remote attackers to bypass authentication via crafted he | 1.7% | — |
| CVE-2010-3700 | MED 5.0 | acegisecurity acegi-security VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter. | 1.7% | — |
| CVE-2024-49104 | HIGH 8.8 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2024-49102 | HIGH 8.8 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2024-45034 | HIGH 8.8 | apache airflow Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG folder and get it executed by the scheduler, where the scheduler is not supposed to execute code submitted by the DAG author. Users are advised | 1.7% | — |
| CVE-2024-30046 | MED 5.9 | microsoft .net Visual Studio Denial of Service Vulnerability | 1.7% | — |
| CVE-2020-0987 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0982, CVE-2020-1005. | 1.7% | — |
| CVE-2017-5057 | HIGH 8.8 | google chrome Type confusion in PDFium in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file. | 1.7% | — |
| CVE-2000-0298 | HIGH 7.2 | microsoft windows_2000 The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories. | 1.7% | — |
| CVE-2023-35367 | CRIT 9.8 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2023-35366 | CRIT 9.8 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2014-0705 | HIGH 7.1 | cisco wireless_lan_controller The multicast listener discovery (MLD) service on Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, 7.4 before 7.4.121.0, and 7.5, when MLDv2 Snooping is enabled, allows remote attackers to cause a denial of service (device restart) via a malformed IPv6 ML | 1.7% | — |
| CVE-2011-3294 | MED 4.3 | cisco telepresence_video_communication_servers Cross-site scripting (XSS) vulnerability in the login page in the administrative interface on Cisco TelePresence Video Communication Servers (VCS) with software before X7.0 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP | 1.7% | — |
| CVE-2008-3149 | HIGH 7.8 | f5 firepass_1200 The SNMP daemon in the F5 FirePass 1200 6.0.2 hotfix 3 allows remote attackers to cause a denial of service (daemon crash) by walking the hrSWInstalled OID branch in HOST-RESOURCES-MIB. | 1.7% | — |
| CVE-2024-38286 | HIGH 8.6 | apache tomcat Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time | 1.7% | — |
| CVE-2021-40777 | HIGH 7.8 | adobe media_encoder Adobe Media Encoder version 15.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required t | 1.7% | — |
| CVE-2021-40734 | HIGH 7.8 | adobe audition Adobe Audition version 14.4 (and earlier) is affected by a memory corruption vulnerability when parsing a SVG file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability | 1.7% | — |
| CVE-2020-10868 | HIGH 7.5 | avast antivirus An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to launch the Repair App RPC call from a Low Integrity process. | 1.7% | — |
| CVE-2020-10865 | HIGH 7.5 | avast antivirus An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to make arbitrary changes to the Components section of the Stats.ini file via RPC from a Low Integrity pr | 1.7% | — |
| CVE-2020-10861 | HIGH 7.5 | avast antivirus An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to achieve Arbitrary File Deletion from Avast Program Path via RPC, when Self Defense is Enabled. | 1.7% | — |
| CVE-2024-21344 | MED 5.9 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 1.7% | — |
| CVE-2022-39951 | HIGH 7.2 | fortinet fortiweb A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to execute unauthorized code or comm | 1.7% | — |
| CVE-2022-33637 | MED 6.5 | microsoft defender_for_endpoint Microsoft Defender for Endpoint Tampering Vulnerability | 1.7% | — |
| CVE-2021-46462 | HIGH 7.5 | f5 njs njs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via njs_object_set_prototype in /src/njs_object.c. | 1.7% | — |
| CVE-2008-2730 | MED 5.0 | cisco unified_communications_manager The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, | 1.7% | — |