IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2015-4291 HIGH 7.8 cisco ios_xe Cisco IOS XE 2.x before 2.4.3 and 2.5.x before 2.5.1 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted series of fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCtd72617. 2.0% —
CVE-2025-22828 MED 4.3 apache cloudstack CloudStack users can add and read comments (annotations) on resources they are authorised to access.  Due to an access validation issue that affects Apache CloudStack versions from 4.16.0, users who have access, prior access or knowledge of resource UUIDs can 2.0% —
CVE-2023-36892 HIGH 8.0 microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability 2.0% —
CVE-2023-36891 HIGH 8.0 microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability 2.0% —
CVE-2023-21709 CRIT 9.8 microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 2.0% —
CVE-2020-2012 HIGH 7.5 paloaltonetworks pan-os Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panorama management interface to read arbitrary files on the system 2.0% —
CVE-2019-1962 HIGH 8.6 cisco nx-os A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause process crashes, which can result in a denial of service (DoS) condition on an affected system. The vulnerability is due to 2.0% —
CVE-2019-12657 HIGH 7.5 cisco ios_xe A vulnerability in Unified Threat Defense (UTD) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper validation of IPv6 packets through the UTD feature. An attacker 2.0% —
CVE-2019-0874 MED 6.1 microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'. 2.0% —
CVE-2017-14010 HIGH 7.8 spidercontrol scada_microbrowser In SpiderControl MicroBrowser Windows XP, Vista 7, 8 and 10, Versions 1.6.30.144 and prior, an uncontrolled search path element vulnerability has been identified which could be exploited by placing a specially crafted DLL file in the search path. If the malic 2.0% —
CVE-2015-4328 MED 4.0 cisco telepresence_video_communication_server_software Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly checks for a user account's read-only attribute, which allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, as demonstrated by read or wri 2.0% —
CVE-2015-2829 HIGH 7.8 citrix netscaler_application_delivery_controller_firmware Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.5 Build 53.9 through 55.8 and 10.5.e Build 53-9010.e allow remote attackers to cause a denial of service (reboot) via unspecified vectors. 2.0% —
CVE-2011-0355 HIGH 7.8 cisco 1000v_virtual_ethernet_module_\(vem\) Cisco Nexus 1000V Virtual Ethernet Module (VEM) 4.0(4) SV1(1) through SV1(3b), as used in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, does not properly handle dropped packets, which allows guest OS users to cause a denial of service (ESX or ESXi host OS crash 2.0% —
CVE-2008-4540 LOW 2.1 microsoft windows_mobile Windows Mobile 6 on the HTC Hermes device makes WLAN passwords available to an auto-completion mechanism for the password input field, which allows physically proximate attackers to bypass password authentication and obtain WLAN access. 2.0% —
CVE-2007-1069 HIGH 7.8 vmware workstation The memory management in VMware Workstation before 5.5.4 allows attackers to cause a denial of service (Windows virtual machine crash) by triggering certain general protection faults (GPF). 2.0% —
CVE-2006-1357 MED 4.3 f5 firepass_4100 Cross-site scripting (XSS) vulnerability in my.support.php3 in F5 Firepass 4100 SSL VPN 5.4.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter. 2.0% —
CVE-2026-23795 MED 4.9 apache syncope Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with adequate entitlements to create or edit Keymaster parameters via Console can construct malicious XML text to launch an XXE attack, thereby caus 2.0% —
CVE-2023-29247 MED 5.4 apache airflow Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0. 2.0% —
CVE-2022-33879 LOW 3.3 apache tika The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 a 2.0% —
CVE-2020-4952 HIGH 8.8 ibm security_guardium IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper access control. IBM X-Force ID: 192028. 2.0% —
CVE-2020-3179 HIGH 7.5 cisco asa_5505_firmware A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vul 2.0% —
CVE-2020-1482 MED 6.3 microsoft sharepoint_enterprise_server <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially 2.0% —
CVE-2019-12654 HIGH 7.5 cisco ios_xe A vulnerability in the common Session Initiation Protocol (SIP) library of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerabil 2.0% —
CVE-2019-12653 HIGH 7.5 cisco ios_xe A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper parsi 2.0% —
CVE-2019-12647 HIGH 7.5 cisco ios_xe A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability exists because the affected software incorrectly handles memory structures, 2.0% —