IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2015-8960 HIGH 8.1 ietf transport_layer_security The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret k 1.9% —
CVE-2025-21217 MED 6.5 microsoft windows_10_1507 Windows NTLM Spoofing Vulnerability 1.9% —
CVE-2022-35802 HIGH 8.1 microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability 1.9% —
CVE-2021-36774 MED 6.5 apache kylin Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server within 1.9% —
CVE-2016-1367 HIGH 7.5 cisco adaptive_security_appliance_software The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 allows remote attackers to cause a denial of service (device reload) via crafted DHCPv6 packets, aka Bug ID CSCus23248. 1.9% —
CVE-2016-1348 HIGH 7.5 cisco ios_xe Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Relay message, aka Bug ID CSCus55821. 1.9% —
CVE-2016-1268 HIGH 7.5 juniper screenos The administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attackers to cause a denial of service (reboot) via a crafted SSL packet. 1.9% —
CVE-2015-4196 MED 5.0 cisco unified_communications_domain_manager Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote attackers to obtain root access by leveraging knowledge of this password and entering it in an SSH se 1.9% —
CVE-2023-23477 HIGH 8.1 ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513. 1.9% —
CVE-2021-4287 MED 5.0 microsoft binwalk A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/binwalk/modules/extractor.py of the component Archive Extraction Handler. The manipulation leads to symlink foll 1.9% —
CVE-2021-1259 MED 6.5 cisco sd-wan_vmanage A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain write access to sensitive files on an affected system. The vulnerability is due to 1.9% —
CVE-2020-8187 HIGH 7.5 citrix application_delivery_controller_firmware Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticated users to perform a denial of service attack. 1.9% —
CVE-2017-2347 MED 6.5 juniper junos A denial of service vulnerability in rpd daemon of Juniper Networks Junos OS allows a malformed MPLS ping packet to crash the rpd daemon if MPLS OAM is configured. Repeated crashes of the rpd daemon can result in an extended denial of service condition for the 1.9% —
CVE-2014-0722 MED 5.0 cisco unified_communications_manager The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers to cause a denial of service (performance degradation) via unspecified use of this application, aka Bug ID CSCu 1.9% —
CVE-2014-0662 HIGH 7.1 cisco telepresence_video_communication_server_software The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a denial of service (process failure) via a crafted SDP message, aka Bug ID CSCue97632. 1.9% —
CVE-2014-0660 HIGH 7.1 cisco telepresence_isdn_gateway_software Cisco TelePresence ISDN Gateway with software before 2.2(1.92) allows remote attackers to cause a denial of service (D-channel call outage) via a crafted Q.931 STATUS message, aka Bug ID CSCui50360. 1.9% —
CVE-2004-0211 LOW 2.1 microsoft windows_2003_server The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program. 1.9% —
CVE-2002-0034 MED 4.6 microsoft windows_2000 The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than ex 1.9% —
CVE-2021-38161 HIGH 8.1 apache traffic_server Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8. 1.9% —
CVE-2021-34517 MED 5.3 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 1.9% —
CVE-2020-13926 CRIT 9.8 apache kylin Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection attack is possible. Use 1.9% —
CVE-2023-36437 HIGH 8.8 microsoft azure_pipelines_agent Azure DevOps Server Remote Code Execution Vulnerability 2.0% —
CVE-2020-2009 HIGH 7.2 paloaltonetworks pan-os An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and write of an arbitrary file on all firewalls managed by the Pano 2.0% —
CVE-2017-7090 HIGH 7.5 apple icloud An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" compone 2.0% —
CVE-2016-4760 MED 6.5 apple iphone_os WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to conduct DNS rebinding attacks against non-HTTP Safari sessions by leveraging HTTP/0.9 support. 2.0% —