58.586 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.586 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2009-2872 | MED 6.8 | cisco ios Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via a malformed packet that is not properly handled during switching from one tunnel t | 2.3% | — |
| CVE-2008-2062 | MED 5.0 | cisco unified_communications_manager The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) before 4.2(3)SR4, and 4.3 before 4.3(2)SR1, allows remote attackers to bypass authentication, and obtain cluster configuration information and statisti | 2.3% | — |
| CVE-2001-0131 | LOW 3.3 | apache http_server htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack. | 2.3% | — |
| CVE-2022-37981 | MED 4.3 | microsoft windows_10 Windows Event Logging Service Denial of Service Vulnerability | 2.3% | — |
| CVE-2021-40474 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2001-1071 | MED 5.0 | cisco catos Cisco IOS 12.2 and earlier running Cisco Discovery Protocol (CDP) allows remote attackers to cause a denial of service (memory consumption) via a flood of CDP neighbor announcements. | 2.3% | — |
| CVE-2024-22255 | HIGH 7.1 | vmware cloud_foundation VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process. | 2.3% | — |
| CVE-2025-62454 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 2.3% | — |
| CVE-2024-43575 | HIGH 7.5 | microsoft windows_server_2016 Windows Hyper-V Denial of Service Vulnerability | 2.3% | — |
| CVE-2024-43567 | HIGH 7.5 | microsoft windows_server_2012 Windows Hyper-V Denial of Service Vulnerability | 2.3% | — |
| CVE-2024-30070 | HIGH 7.5 | microsoft windows_server_2012 DHCP Server Service Denial of Service Vulnerability | 2.3% | — |
| CVE-2025-32706 | HIGH 7.8 | microsoft windows_10_1507 Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 2.3% | |
| CVE-2024-23672 | MED 6.3 | apache tomcat Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, fro | 2.3% | — |
| CVE-2020-0753 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0754. | 2.3% | — |
| CVE-2023-36603 | HIGH 7.5 | microsoft windows_10_1809 Windows TCP/IP Denial of Service Vulnerability | 2.3% | — |
| CVE-2023-36602 | HIGH 7.5 | microsoft windows_10_1507 Windows TCP/IP Denial of Service Vulnerability | 2.3% | — |
| CVE-2022-38045 | HIGH 8.8 | microsoft windows_10 Windows Server Service Elevation of Privilege Vulnerability | 2.3% | — |
| CVE-2021-0276 | CRIT 9.8 | juniper steel-belted_radius_carrier A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending specific packets causing the radius daemon to crash resulting with a Denial of Servi | 2.3% | — |
| CVE-2019-8027 | MED 6.3 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Successful e | 2.3% | — |
| CVE-2015-6255 | MED 4.3 | cisco unified_web_and_e-mail_interaction_manager Cross-site scripting (XSS) vulnerability in Cisco Unified Web and E-Mail Interaction Manager 9.0(2) allows remote attackers to inject arbitrary web script or HTML via a crafted chat message, aka Bug ID CSCuo89051. | 2.3% | — |
| CVE-2022-28129 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. | 2.3% | — |
| CVE-2021-28434 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28358 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28357 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28355 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.3% | — |