58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2008-3817 | HIGH 7.8 | cisco adaptive_security_appliance_5500_series Memory leak in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 8.0 before 8.0(4) and 8.1 before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via an unspecified sequence of packets, related to | 2.0% | — |
| CVE-2008-3811 | HIGH 7.8 | cisco ios Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabled, allows remote attackers to cause a denial of service (device reload) via segmented SCCP messages, aka Cisco Bug ID CSCsi17020, a different vulnerability tha | 2.0% | — |
| CVE-2007-5584 | HIGH 7.8 | cisco firewall_services_module Unspecified vulnerability in Cisco Firewall Services Module (FWSM) 3.2(3) allows remote attackers to cause a denial of service (device reload) via crafted "data in the control-plane path with Layer 7 Application Inspections." | 2.0% | — |
| CVE-2007-5537 | HIGH 7.8 | cisco unified_callmanager Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote attackers to cause a denial of service (kernel panic) via a flood of SIP INVITE messages to UDP port 5060, which triggers resource ex | 2.0% | — |
| CVE-2007-4789 | HIGH 7.8 | cisco content_switching_module_with_ssl Cisco Content Switching Modules (CSM) 4.2 before 4.2.7, and Cisco Content Switching Module with SSL (CSM-S) 2.1 before 2.1.6, when service termination is enabled, allow remote attackers to cause a denial of service (reboot) via unspecified vectors related to h | 2.0% | — |
| CVE-2007-4788 | HIGH 7.8 | cisco content_switching_module_with_ssl Cisco Content Switching Modules (CSM) 4.2 before 4.2.3a, and Cisco Content Switching Module with SSL (CSM-S) 2.1 before 2.1.2a, allow remote attackers to cause a denial of service (CPU consumption or reboot) via sets of out-of-order TCP packets with unspecifie | 2.0% | — |
| CVE-2007-3923 | HIGH 7.8 | cisco wide_area_application_services The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the NM-WAE-502 network module, when Edge Services are configured, allows remote attackers to cause a denial o | 2.0% | — |
| CVE-2007-3775 | HIGH 7.8 | cisco unified_communications_manager Unspecified vulnerability in Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allows remote attackers to cause a denial of service (loss of cluster services) via unspecified vectors, aka (1) CSCsj09859 and (2 | 2.0% | — |
| CVE-2007-3362 | HIGH 7.8 | ageet agephone ageet AGEphone before 1.6.2, running on Windows Mobile 5 on the HTC HyTN Pocket PC device, allows remote attackers to (1) cause a denial of service (call disruption and device hang) via a SIP message with a malformed header and (2) cause a denial of service (c | 2.0% | — |
| CVE-2007-1826 | HIGH 7.8 | cisco unified_callmanager Unspecified vulnerability in the IPSec Manager Service for Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allows remote attackers to cause a denial of service (loss of cluster services) via a " | 2.0% | — |
| CVE-2025-24991 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | 2.0% | |
| CVE-2022-35744 | CRIT 9.8 | microsoft windows_10_1507 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2020-1595 | CRIT 9.9 | microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application | 2.0% | — |
| CVE-2019-9969 | HIGH 7.8 | xnview xnview_classic XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x385399. | 2.0% | — |
| CVE-2022-35774 | MED 4.9 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2021-43255 | MED 5.5 | microsoft 365_apps Microsoft Office Trust Center Spoofing Vulnerability | 2.0% | — |
| CVE-2021-42732 | HIGH 7.8 | adobe indesign Access of Memory Location After End of Buffer (CWE-788) | 2.0% | — |
| CVE-2024-49019 | HIGH 7.8 | microsoft windows_server_2008 Active Directory Certificate Services Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2024-30090 | HIGH 7.0 | microsoft windows_10_1507 Microsoft Streaming Service Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2023-29330 | HIGH 8.8 | microsoft teams Microsoft Teams Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2022-25598 | HIGH 7.5 | apache dolphinscheduler Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher. | 2.0% | — |
| CVE-2021-21984 | CRIT 9.8 | vmware vrealize_business_for_cloud VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious actor with network access may exploit this issue causing unauthorised remote code execution on vRealize Business | 2.0% | — |
| CVE-2023-25696 | CRIT 9.8 | apache apache-airflow-providers-apache-hive Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3. | 2.0% | — |
| CVE-2020-3241 | MED 6.5 | cisco ucs_director A vulnerability in the orchestration tasks of Cisco UCS Director could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input on the web-based | 2.0% | — |
| CVE-2019-1266 | MED 6.1 | microsoft exchange_server A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. | 2.0% | — |