58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-25693 | CRIT 9.8 | apache apache-airflow-providers-apache-sqoop Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1. | 1.9% | — |
| CVE-2020-2006 | HIGH 7.2 | paloaltonetworks pan-os A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated user to potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions e | 1.9% | — |
| CVE-2018-0460 | MED 6.5 | cisco network_functions_virtualization_infrastructure A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system. The vulnerability is due to insufficient authorization and parameter validation checks | 1.9% | — |
| CVE-2017-3796 | HIGH 7.2 | cisco webex_meetings_server A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute predetermined shell commands on other hosts. More Information: CSCuz03353. Known Affected Releases: 2.6. | 1.9% | — |
| CVE-2015-0685 | HIGH 7.8 | cisco ios_xe Cisco IOS XE before 3.7.5S on ASR 1000 devices does not properly handle route adjacencies, which allows remote attackers to cause a denial of service (device hang) via crafted IP packets, aka Bug ID CSCub31873. | 1.9% | — |
| CVE-2015-0652 | HIGH 7.8 | cisco expressway_software The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled excepti | 1.9% | — |
| CVE-2014-3818 | HIGH 7.8 | juniper junos Juniper Junos OS 9.1 through 11.4 before 11.4R11, 12.1 before R10, 12.1X44 before D40, 12.1X46 before D30, 12.1X47 before D11 and 12.147-D15, 12.1X48 before D41 and D62, 12.2 before R8, 12.2X50 before D70, 12.3 before R6, 13.1 before R4-S2, 13.1X49 before D49, | 1.9% | — |
| CVE-2013-3386 | HIGH 7.8 | cisco ironport_asyncos The IronPort Spam Quarantine (ISQ) component in the web framework in IronPort AsyncOS on Cisco Email Security Appliance devices before 7.1.5-106 and 7.3, 7.5, and 7.6 before 7.6.3-019 and Content Security Management Appliance devices before 7.9.1-102 and 8.0 b | 1.9% | — |
| CVE-2012-4629 | HIGH 7.8 | cisco asa_cx_context-aware_security The Cisco ASA-CX Context-Aware Security module before 9.0.2-103 for Adaptive Security Appliances (ASA) devices, and Prime Security Manager (aka PRSM) before 9.0.2-103, allows remote attackers to cause a denial of service (disk consumption and application hang) | 1.9% | — |
| CVE-2012-3946 | MED 5.0 | cisco ios Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bu | 1.9% | — |
| CVE-2012-3079 | HIGH 7.8 | cisco ios Cisco IOS 12.2 allows remote attackers to cause a denial of service (CPU consumption) by establishing many IPv6 neighbors, aka Bug ID CSCtn78957. | 1.9% | — |
| CVE-2022-34717 | HIGH 8.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2019-14209 | CRIT 9.8 | foxitsoftware phantompdf An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to Heap Corruption due to data desynchrony when adding AcroForm. | 1.9% | — |
| CVE-2018-1000204 | MED 5.3 | canonical ubuntu_linux Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV and an empty 6-byte cmdp. This may lead to copying up to 1000 kernel heap pages to the userspace. This has been fixed upstream in https://gi | 1.9% | — |
| CVE-2023-35381 | HIGH 8.8 | microsoft windows_10_1507 Windows Fax Service Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-24534 | HIGH 7.5 | microsoft windows_10 Win32 Stream Enumeration Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2013-3415 | HIGH 7.8 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software 8.4.x before 8.4(3) and 8.6.x before 8.6(1.3) does not properly manage memory upon an AnyConnect SSL VPN client disconnection, which allows remote attackers to cause a denial of service (memory consumption, and | 1.9% | — |
| CVE-2003-0216 | HIGH 9.3 | cisco catos Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password. | 1.9% | — |
| CVE-2023-24942 | HIGH 7.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.9% | — |
| CVE-2021-25236 | MED 5.3 | trendmicro officescan A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a specific sweep. | 1.9% | — |
| CVE-2020-27016 | HIGH 8.8 | trendmicro interscan_messaging_security_virtual_appliance Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a cross-site request forgery (CSRF) vulnerability which could allow an attacker to modify policy rules by tricking an authenticated administrator into accessing an attacker | 1.9% | — |
| CVE-2017-6612 | HIGH 8.6 | cisco asr_5000_series_software A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17.3.9.62033 through 21.1.2 could allow an unauthenticated, remote attacker to redirect HTTP traffic sent to an affected device. More Information: CSC | 1.9% | — |
| CVE-2017-0298 | HIGH 7.3 | microsoft windows_10 A DCOM object in Helppane.exe in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016, when configured to run as the interactive us | 1.9% | — |
| CVE-2022-38046 | HIGH 7.5 | microsoft windows_10 Web Account Manager Information Disclosure Vulnerability | 1.9% | — |
| CVE-2018-0333 | MED 5.8 | cisco secure_firewall_management_center A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass | 1.9% | — |