IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2011-2497 HIGH 8.3 linux linux_kernel Integer underflow in the l2cap_config_req function in net/bluetooth/l2cap_core.c in the Linux kernel before 3.0 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a small command-size val 2.0% —
CVE-2025-46392 MED 6.5 apache commons_configuration Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted configurations or using unexpected usage pat 2.0% —
CVE-2019-1976 CRIT 9.8 cisco industrial_network_director A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper access 2.0% —
CVE-2018-0298 HIGH 7.5 cisco firepower_extensible_operating_system A vulnerability in the web UI of Cisco FXOS and Cisco UCS Fabric Interconnect Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerability is due to incorrect input validation in the web UI. An at 2.0% —
CVE-2026-62912 MED 6.5 microsoft exchange_server Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. 2.0% —
CVE-2023-36787 HIGH 8.8 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 2.0% —
CVE-2022-30134 MED 6.5 microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability 2.0% —
CVE-2019-9077 HIGH 7.8 canonical ubuntu_linux An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c via a malformed MIPS option section. 2.0% —
CVE-2018-4267 HIGH 8.8 apple icloud Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6. 2.0% —
CVE-2020-9479 MED 5.5 apache asterixdb When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory. This issue affected Apache AsterixDB unreleased builds between commits 580b81aa5e8888b8e1b0620521a1c9680e54df73 and 28c0ee84f1387ab5d0659e9 2.0% —
CVE-2019-1714 HIGH 8.6 cisco adaptive_security_appliance_software A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense 2.0% —
CVE-2013-5046 MED 6.2 microsoft internet_explorer Microsoft Internet Explorer 7 through 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability." 2.0% —
CVE-2013-3107 MED 4.3 vmware vcenter_server_appliance VMware vCenter Server 5.1 before Update 1, when anonymous LDAP binding for Active Directory is enabled, allows remote attackers to bypass authentication by providing a valid username in conjunction with an empty password. 2.0% —
CVE-2007-0966 HIGH 7.8 cisco firewall_services_module Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.11), when the HTTPS server is enabled, allows remote attackers to cause a denial of service (device reboot) via certain HTTPS traffic. 2.0% —
CVE-2025-47978 MED 6.5 microsoft windows_server_2022 Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. 2.0% —
CVE-2023-33170 HIGH 8.1 fedoraproject fedora ASP.NET and Visual Studio Security Feature Bypass Vulnerability 2.0% —
CVE-2023-21728 HIGH 7.5 microsoft windows_10_1607 Windows Netlogon Denial of Service Vulnerability 2.0% —
CVE-2023-21683 HIGH 7.5 microsoft windows_10_1607 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 2.0% —
CVE-2023-21677 HIGH 7.5 microsoft windows_10_1607 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 2.0% —
CVE-2023-21527 HIGH 7.5 microsoft windows_10_1607 Windows iSCSI Service Denial of Service Vulnerability 2.0% —
CVE-2022-23206 HIGH 7.5 apache traffic_control In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach. 2.0% —
CVE-2021-33746 HIGH 8.0 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 2.0% —
CVE-2016-1295 MED 5.3 cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775. 2.0% —
CVE-2010-1729 MED 4.3 apple safari WebKit.dll in WebKit, as used in Safari.exe 4.531.9.1 in Apple Safari, allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop. 2.0% —
CVE-2010-0151 HIGH 7.8 cisco firewall_services_module The Cisco Firewall Services Module (FWSM) 4.0 before 4.0(8), as used in for the Cisco Catalyst 6500 switches, Cisco 7600 routers, and ASA 5500 Adaptive Security Appliances, allows remote attackers to cause a denial of service (crash) via a malformed Skinny Cli 2.0% —