58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-8960 | HIGH 8.1 | ietf transport_layer_security The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret k | 1.9% | — |
| CVE-2025-21217 | MED 6.5 | microsoft windows_10_1507 Windows NTLM Spoofing Vulnerability | 1.9% | — |
| CVE-2022-35802 | HIGH 8.1 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2021-36774 | MED 6.5 | apache kylin Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server within | 1.9% | — |
| CVE-2016-1367 | HIGH 7.5 | cisco adaptive_security_appliance_software The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 allows remote attackers to cause a denial of service (device reload) via crafted DHCPv6 packets, aka Bug ID CSCus23248. | 1.9% | — |
| CVE-2016-1348 | HIGH 7.5 | cisco ios_xe Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Relay message, aka Bug ID CSCus55821. | 1.9% | — |
| CVE-2016-1268 | HIGH 7.5 | juniper screenos The administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attackers to cause a denial of service (reboot) via a crafted SSL packet. | 1.9% | — |
| CVE-2015-4196 | MED 5.0 | cisco unified_communications_domain_manager Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote attackers to obtain root access by leveraging knowledge of this password and entering it in an SSH se | 1.9% | — |
| CVE-2023-23477 | HIGH 8.1 | ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513. | 1.9% | — |
| CVE-2021-4287 | MED 5.0 | microsoft binwalk A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/binwalk/modules/extractor.py of the component Archive Extraction Handler. The manipulation leads to symlink foll | 1.9% | — |
| CVE-2021-1259 | MED 6.5 | cisco sd-wan_vmanage A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain write access to sensitive files on an affected system. The vulnerability is due to | 1.9% | — |
| CVE-2020-8187 | HIGH 7.5 | citrix application_delivery_controller_firmware Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticated users to perform a denial of service attack. | 1.9% | — |
| CVE-2017-2347 | MED 6.5 | juniper junos A denial of service vulnerability in rpd daemon of Juniper Networks Junos OS allows a malformed MPLS ping packet to crash the rpd daemon if MPLS OAM is configured. Repeated crashes of the rpd daemon can result in an extended denial of service condition for the | 1.9% | — |
| CVE-2014-0722 | MED 5.0 | cisco unified_communications_manager The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers to cause a denial of service (performance degradation) via unspecified use of this application, aka Bug ID CSCu | 1.9% | — |
| CVE-2014-0662 | HIGH 7.1 | cisco telepresence_video_communication_server_software The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a denial of service (process failure) via a crafted SDP message, aka Bug ID CSCue97632. | 1.9% | — |
| CVE-2014-0660 | HIGH 7.1 | cisco telepresence_isdn_gateway_software Cisco TelePresence ISDN Gateway with software before 2.2(1.92) allows remote attackers to cause a denial of service (D-channel call outage) via a crafted Q.931 STATUS message, aka Bug ID CSCui50360. | 1.9% | — |
| CVE-2004-0211 | LOW 2.1 | microsoft windows_2003_server The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program. | 1.9% | — |
| CVE-2002-0034 | MED 4.6 | microsoft windows_2000 The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than ex | 1.9% | — |
| CVE-2021-38161 | HIGH 8.1 | apache traffic_server Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8. | 1.9% | — |
| CVE-2021-34517 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1.9% | — |
| CVE-2020-13926 | CRIT 9.8 | apache kylin Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection attack is possible. Use | 1.9% | — |
| CVE-2023-36437 | HIGH 8.8 | microsoft azure_pipelines_agent Azure DevOps Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2020-2009 | HIGH 7.2 | paloaltonetworks pan-os An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and write of an arbitrary file on all firewalls managed by the Pano | 2.0% | — |
| CVE-2017-7090 | HIGH 7.5 | apple icloud An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" compone | 2.0% | — |
| CVE-2016-4760 | MED 6.5 | apple iphone_os WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to conduct DNS rebinding attacks against non-HTTP Safari sessions by leveraging HTTP/0.9 support. | 2.0% | — |