IT
58.458 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.458 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2010-1575 HIGH 7.5 cisco content_services_switch_11500 The Cisco Content Services Switch (CSS) 11500 with software 08.20.1.01 conveys authentication data through ClientCert-* headers but does not delete client-supplied ClientCert-* headers, which might allow remote attackers to bypass authentication via crafted he 1.7% —
CVE-2010-3700 MED 5.0 acegisecurity acegi-security VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter. 1.7% —
CVE-2024-49104 HIGH 8.8 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.7% —
CVE-2024-49102 HIGH 8.8 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.7% —
CVE-2024-45034 HIGH 8.8 apache airflow Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG folder and get it executed by the scheduler, where the scheduler is not supposed to execute code submitted by the DAG author. Users are advised 1.7% —
CVE-2024-30046 MED 5.9 microsoft .net Visual Studio Denial of Service Vulnerability 1.7% —
CVE-2020-0987 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0982, CVE-2020-1005. 1.7% —
CVE-2017-5057 HIGH 8.8 google chrome Type confusion in PDFium in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file. 1.7% —
CVE-2000-0298 HIGH 7.2 microsoft windows_2000 The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories. 1.7% —
CVE-2023-35367 CRIT 9.8 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.7% —
CVE-2023-35366 CRIT 9.8 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.7% —
CVE-2014-0705 HIGH 7.1 cisco wireless_lan_controller The multicast listener discovery (MLD) service on Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, 7.4 before 7.4.121.0, and 7.5, when MLDv2 Snooping is enabled, allows remote attackers to cause a denial of service (device restart) via a malformed IPv6 ML 1.7% —
CVE-2011-3294 MED 4.3 cisco telepresence_video_communication_servers Cross-site scripting (XSS) vulnerability in the login page in the administrative interface on Cisco TelePresence Video Communication Servers (VCS) with software before X7.0 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP 1.7% —
CVE-2008-3149 HIGH 7.8 f5 firepass_1200 The SNMP daemon in the F5 FirePass 1200 6.0.2 hotfix 3 allows remote attackers to cause a denial of service (daemon crash) by walking the hrSWInstalled OID branch in HOST-RESOURCES-MIB. 1.7% —
CVE-2024-38286 HIGH 8.6 apache tomcat Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time 1.7% —
CVE-2021-40777 HIGH 7.8 adobe media_encoder Adobe Media Encoder version 15.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required t 1.7% —
CVE-2021-40734 HIGH 7.8 adobe audition Adobe Audition version 14.4 (and earlier) is affected by a memory corruption vulnerability when parsing a SVG file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability 1.7% —
CVE-2020-10868 HIGH 7.5 avast antivirus An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to launch the Repair App RPC call from a Low Integrity process. 1.7% —
CVE-2020-10865 HIGH 7.5 avast antivirus An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to make arbitrary changes to the Components section of the Stats.ini file via RPC from a Low Integrity pr 1.7% —
CVE-2020-10861 HIGH 7.5 avast antivirus An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to achieve Arbitrary File Deletion from Avast Program Path via RPC, when Self Defense is Enabled. 1.7% —
CVE-2024-21344 MED 5.9 microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability 1.7% —
CVE-2022-39951 HIGH 7.2 fortinet fortiweb A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to execute unauthorized code or comm 1.7% —
CVE-2022-33637 MED 6.5 microsoft defender_for_endpoint Microsoft Defender for Endpoint Tampering Vulnerability 1.7% —
CVE-2021-46462 HIGH 7.5 f5 njs njs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via njs_object_set_prototype in /src/njs_object.c. 1.7% —
CVE-2008-2730 MED 5.0 cisco unified_communications_manager The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, 1.7% —