58.586 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.586 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-7172 | HIGH 7.8 | apple icloud An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affecte | 2.3% | — |
| CVE-2013-5530 | HIGH 9.0 | cisco identity_services_engine_software The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.3 before 1.1.3.124-7, 1.1.4 before 1.1.4.218-7, and 1.2 before 1.2.0.899-2 allows remote authenticated users to | 2.3% | — |
| CVE-2010-2665 | MED 4.3 | opera opera_browser Cross-site scripting (XSS) vulnerability in Opera before 10.54 on Windows and Mac OS X, and before 10.11 on UNIX platforms, allows remote attackers to inject arbitrary web script or HTML via a data: URI, related to incorrect detection of the "opening site." | 2.3% | — |
| CVE-2013-1137 | HIGH 7.8 | cisco unified_presence_server Cisco Unified Presence Server (CUPS) 8.6, 9.0, and 9.1 before 9.1.1 allows remote attackers to cause a denial of service (CPU consumption) via crafted packets to the SIP TCP port, aka Bug ID CSCua89930. | 2.3% | — |
| CVE-2023-41834 | MED 6.1 | apache flink_stateful_functions Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted HTTP requests. Attackers could | 2.3% | — |
| CVE-2018-8427 | MED 5.5 | microsoft excel_viewer An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Office | 2.3% | — |
| CVE-2016-6801 | HIGH 8.8 | apache jackrabbit Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows rem | 2.3% | — |
| CVE-2010-1138 | MED 5.0 | vmware ace The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation 6.5.x before 6.5.4 build 246459 on Windows, VMware Player 3.0 before 3.0.1 build 227600, VMware Player 2.5.x before 2.5.4 build 246459 on Windows, VMware ACE 2 | 2.3% | — |
| CVE-2025-32706 | HIGH 7.8 | microsoft windows_10_1507 Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 2.3% | |
| CVE-2024-28913 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2013-5664 | MED 4.3 | paloaltonetworks pan-os Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS before 4.1.13 and 5.0.x before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via crafted data, aka Ref ID 50908. | 2.3% | — |
| CVE-2025-53521 | CRIT 9.8 | f5 big-ip_access_policy_manager When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 2.3% | |
| CVE-2021-28477 | HIGH 7.0 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2016-1265 | CRIT 9.8 | juniper junos_space A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak | 2.3% | — |
| CVE-2026-75604 | CRIT 9.0 | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in rout | 2.3% | — |
| CVE-2022-31780 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. | 2.3% | — |
| CVE-2022-23294 | HIGH 8.8 | microsoft windows_10 Windows Event Tracing Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2020-3382 | CRIT 9.8 | cisco data_center_network_manager A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability exists be | 2.3% | — |
| CVE-2018-14615 | MED 5.5 | linux linux_kernel An issue was discovered in the Linux kernel through 4.17.10. There is a buffer overflow in truncate_inline_inode() in fs/f2fs/inline.c when umounting an f2fs image, because a length value may be negative. | 2.3% | — |
| CVE-2022-20704 | CRIT 10.0 | cisco rv160_firmware Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot | 2.3% | — |
| CVE-2018-0132 | HIGH 8.6 | cisco carrier_routing_system A vulnerability in the forwarding information base (FIB) code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause inconsistency between the routing information base (RIB) and the FIB, resulting in a denial of service (DoS) conditi | 2.3% | — |
| CVE-2018-0094 | HIGH 7.5 | cisco unified_computing_system_central_software A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high CPU utilization on the targeted device. The vulnerability is due to insuff | 2.3% | — |
| CVE-2018-0086 | HIGH 8.6 | cisco unified_customer_voice_portal A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to malformed SIP INVITE tra | 2.3% | — |
| CVE-2017-6729 | HIGH 7.5 | cisco asr_5000_software A vulnerability in the Border Gateway Protocol (BGP) processing functionality of the Cisco StarOS operating system for Cisco ASR 5000 Series Routers and Cisco Virtualized Packet Core (VPC) Software could allow an unauthenticated, remote attacker to cause the B | 2.3% | — |
| CVE-2017-12293 | HIGH 8.6 | cisco webex_meetings_server A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient limitations on the number of connections that can be made to the affected soft | 2.3% | — |