58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-6779 | HIGH 7.5 | cisco emergency_responder Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service | 2.0% | — |
| CVE-2009-1202 | MED 4.3 | cisco adaptive_security_appliance WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass certain protection mechanisms involving URL rewriting and HTML rewriting, and conduct cross-site scripting (XSS) attacks, by | 2.0% | — |
| CVE-2023-33129 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-29369 | MED 6.5 | microsoft windows_server_2012 Remote Procedure Call Runtime Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-24938 | MED 6.5 | microsoft windows_10_1809 Windows CryptoAPI Denial of Service Vulnerability | 2.0% | — |
| CVE-2022-25763 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. | 2.0% | — |
| CVE-2021-1223 | HIGH 7.5 | cisco ios_xe Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An a | 2.0% | — |
| CVE-2018-4261 | HIGH 8.8 | apple icloud Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6. | 2.0% | — |
| CVE-2015-1210 | MED 5.0 | canonical ubuntu_linux The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly consider fr | 2.0% | — |
| CVE-2008-0028 | HIGH 7.1 | cisco adaptive_security_appliance_software Unspecified vulnerability in Cisco PIX 500 Series Security Appliance and 5500 Series Adaptive Security Appliance (ASA) before 7.2(3)6 and 8.0(3), when the Time-to-Live (TTL) decrement feature is enabled, allows remote attackers to cause a denial of service (de | 2.0% | — |
| CVE-2024-30311 | MED 5.5 | adobe acrobat Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Expl | 2.0% | — |
| CVE-2023-28241 | HIGH 7.5 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability | 2.0% | — |
| CVE-2019-1967 | HIGH 7.5 | cisco nx-os A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to excessive use of system resources | 2.0% | — |
| CVE-2019-1964 | HIGH 8.6 | cisco nx-os A vulnerability in the IPv6 traffic processing of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an unexpected restart of the netstack process on an affected device. The vulnerability is due to improper validation of IPv6 traffic | 2.0% | — |
| CVE-2019-12206 | CRIT 9.8 | f5 njs njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in nxt_utf8_encode in nxt_utf8.c. | 2.0% | — |
| CVE-2017-6613 | MED 5.8 | cisco prime_network_registrar A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause the DNS process to momentarily restart, which could lead to a partial denial of service (DoS) condition on the affected | 2.0% | — |
| CVE-2014-2113 | HIGH 7.8 | cisco ios Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to cause a denial of service (I/O memory consumption and device reload) via a malformed IPv6 packet, aka Bug ID CS | 2.0% | — |
| CVE-2003-1106 | MED 5.0 | The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute. | 2.0% | — |
| CVE-2002-2150 | MED 5.0 | juniper netscreen_screenos Firewalls from multiple vendors empty state tables more slowly than they are filled, which allows remote attackers to flood state tables with packet flooding attacks such as (1) TCP SYN flood, (2) UDP flood, or (3) Crikey CRC Flood, which causes the firewall t | 2.0% | — |
| CVE-2023-38156 | HIGH 7.2 | microsoft azure_hdinsight Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2021-46818 | HIGH 7.8 | adobe media_encoder Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue r | 2.0% | — |
| CVE-2018-0346 | HIGH 7.5 | cisco vbond_orchestrator A vulnerability in the Zero Touch Provisioning service of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect bounds checks for cert | 2.0% | — |
| CVE-2015-2839 | MED 4.3 | citrix netscaler The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the file_name JSON member in params/xen_hotfix/0 to nitro | 2.0% | — |
| CVE-2018-1314 | MED 4.3 | apache hive In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary table or view and expose table metadata and statistics. | 2.0% | — |
| CVE-2015-7750 | MED 5.0 | juniper screenos The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3.0r18 before 6.3.0r18-dnc1, and 6.3.0r19 allows remote attackers to cause a denial of service via a crafted L2T | 2.0% | — |