58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-24503 | MED 5.4 | microsoft remote_desktop_client Remote Desktop Protocol Client Information Disclosure Vulnerability | 2.4% | — |
| CVE-2019-1616 | HIGH 8.6 | cisco nx-os A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of | 2.4% | — |
| CVE-2013-1471 | MED 4.3 | fortinet fortimail Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Add fie | 2.4% | — |
| CVE-2011-0786 | HIGH 7.6 | sun jdk Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, a | 2.4% | — |
| CVE-2024-38230 | MED 6.5 | microsoft windows_server_2012 Windows Standards-Based Storage Management Service Denial of Service Vulnerability | 2.4% | — |
| CVE-2020-8273 | HIGH 8.8 | citrix sd-wan Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8. | 2.4% | — |
| CVE-2009-2049 | MED 5.4 | cisco ios Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1 through 12.2(33)SXI2, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 thr | 2.4% | — |
| CVE-2022-23280 | MED 5.3 | microsoft outlook_2016 Microsoft Outlook for Mac Security Feature Bypass Vulnerability | 2.4% | — |
| CVE-2021-1722 | HIGH 8.1 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2015-6428 | MED 5.0 | cisco dpq3925_8x4_docsis_3.0_wireless_residential_gateway_with_embedded_digital_voice_adapter Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958. | 2.4% | — |
| CVE-2010-0730 | LOW 2.6 | redhat enterprise_linux The MMIO instruction decoder in the Xen hypervisor in the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows guest OS users to cause a denial of service (32-bit guest OS crash) via vectors that trigger an unspecified instruction emulation. | 2.4% | — |
| CVE-2001-1056 | HIGH 7.5 | linux linux_kernel IRC DCC helper in the ip_masq_irc IP masquerading module 2.2 allows remote attackers to bypass intended firewall restrictions by causing the target system to send a "DCC SEND" request to a malicious server which listens on port 6667, which may cause the module | 2.4% | — |
| CVE-1999-0376 | MED 4.6 | microsoft windows_nt Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs. | 2.4% | — |
| CVE-2026-11645 | HIGH 8.8 | google chrome Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 2.4% | |
| CVE-2021-26987 | CRIT 9.8 | netapp element_plug-in_for_vcenter_server Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCe | 2.4% | — |
| CVE-2007-5337 | MED 4.3 | gnome gnome-vfs Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server | 2.4% | — |
| CVE-2006-1671 | MED 5.0 | cisco ons_15310-cl_series Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (card reset) via (1) a "crafted" IP packet to a device with secure mode EMS-to-network-element access, aka bug ID CSC | 2.4% | — |
| CVE-2023-2317 | HIGH 8.6 | typora typora DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run arbitrary JavaScript code in the context of Typora main window via loading typora://app/typemark/updater/update.html in <embed> tag. This vul | 2.4% | — |
| CVE-2020-1528 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Radio Manager API improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted appl | 2.4% | — |
| CVE-2018-17781 | HIGH 7.5 | foxitsoftware phantompdf Foxit PhantomPDF and Reader before 9.3 allow remote attackers to trigger Uninitialized Object Information Disclosure because creation of ArrayBuffer and DataView objects is mishandled. | 2.4% | — |
| CVE-2019-1840 | HIGH 8.6 | cisco prime_network_registrar A vulnerability in the DHCPv6 input packet processor of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to restart the server and cause a denial of service (DoS) condition on the affected system. The vulnerability is due to incomp | 2.4% | — |
| CVE-2019-1837 | MED 5.3 | cisco unified_communications_manager A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI. The vulnerability is due to improper va | 2.4% | — |
| CVE-2018-8396 | MED 4.7 | microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE | 2.4% | — |
| CVE-2015-3108 | MED 5.0 | adobe air Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and | 2.4% | — |
| CVE-2026-45591 | HIGH 7.5 | microsoft .net Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 2.4% | — |