IT
58.462 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.462 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2019-0007 CRIT 9.3 juniper junos The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible to a family of attacks which rely on the use of predictable IP ID sequence numbers as their base method of att 1.7% —
CVE-2024-49080 HIGH 8.8 microsoft windows_10_1507 Windows IP Routing Management Snapin Remote Code Execution Vulnerability 1.7% —
CVE-2024-29133 MED 5.4 apache commons_configuration Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. 1.7% —
CVE-2010-0312 MED 5.0 ibm tivoli_directory_server The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted SecureWay 3.2 Event Registration Request (aka a 1.3.18.0.2.1 1.7% —
CVE-2021-22049 CRIT 9.8 vmware vcenter_server The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request out 1.7% —
CVE-2020-13922 MED 6.5 apache dolphinscheduler Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface. 1.7% —
CVE-2016-8459 CRIT 9.8 linux linux_kernel Possible buffer overflow in storage subsystem. Bad parameters as part of listener responses to RPMB commands could lead to buffer overflow. Product: Android. Versions: Kernel 3.18. Android ID: A-32577972. References: QC-CR#988462. 1.7% —
CVE-2016-8439 CRIT 9.8 linux linux_kernel Possible buffer overflow in trust zone access control API. Buffer overflow may occur due to lack of buffer size checking. Product: Android. Versions: Kernel 3.18. Android ID: A-31625204. References: QC-CR#1027804. 1.7% —
CVE-2010-4114 MED 4.3 hp discovery\&dependency_mapping_inventory Cross-site scripting (XSS) vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.6x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. 1.7% —
CVE-2024-30097 HIGH 8.8 microsoft windows_10_1507 Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability 1.7% —
CVE-2020-1442 MED 6.1 microsoft office_online_server A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request, aka 'Office Web Apps XSS Vulnerability'. 1.7% —
CVE-2019-0759 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows Print Spooler does not properly handle objects in memory, aka 'Windows Print Spooler Information Disclosure Vulnerability'. 1.7% —
CVE-2018-0118 MED 6.1 cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to perform a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected dev 1.7% —
CVE-2016-6437 MED 5.9 cisco wide_area_application_services A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of disk space. The user would see a performa 1.7% —
CVE-2015-4286 MED 5.0 cisco unified_computing_system_central_software The web framework in Cisco UCS Central Software 1.3(0.99) allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuu41377. 1.7% —
CVE-2007-4311 MED 6.8 linux linux_kernel The xfer_secondary_pool function in drivers/char/random.c in the Linux kernel 2.4 before 2.4.35 performs reseed operations on only the first few bytes of a buffer, which might make it easier for attackers to predict the output of the random number generator, r 1.7% —
CVE-2005-1020 HIGH 7.1 cisco ios Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a domain name when using a TACACS+ server to authenticate, (2) when a new SSH session is in the login phas 1.7% —
CVE-2026-50652 HIGH 7.5 microsoft .net_framework Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. 1.7% —
CVE-2024-41937 MED 6.1 apache airflow Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web s 1.7% —
CVE-2024-21420 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.7% —
CVE-2023-36407 HIGH 7.8 microsoft windows_11_21h2 Windows Hyper-V Elevation of Privilege Vulnerability 1.7% —
CVE-2019-15666 MED 4.4 debian debian_linux An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory validation. 1.7% —
CVE-2007-4774 MED 5.9 linux linux_kernel The Linux kernel before 2.4.36-rc1 has a race condition. It was possible to bypass systrace policies by flooding the ptraced process with SIGCONT signals, which can can wake up a PTRACED process. 1.7% —
CVE-2023-28234 HIGH 7.5 microsoft windows_11_21h2 Windows Secure Channel Denial of Service Vulnerability 1.7% —
CVE-2023-28233 HIGH 7.5 microsoft windows_11_21h2 Windows Secure Channel Denial of Service Vulnerability 1.7% —