IT
58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.639 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-42899 HIGH 7.5 microsoft .net Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network. 2.4% —
CVE-2026-33116 HIGH 7.5 microsoft .net Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network. 2.4% —
CVE-2026-32203 HIGH 7.5 microsoft .net Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network. 2.4% —
CVE-2023-36776 HIGH 7.0 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 2.4% —
CVE-2021-40114 MED 6.8 cisco secure_firewall_management_center Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is d 2.4% —
CVE-2019-17657 HIGH 7.5 fortinet fortianalyzer An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via ha 2.4% —
CVE-2014-4064 MED 4.9 microsoft windows_7 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly handle use of the paged kernel pool for allocation o 2.4% —
CVE-2024-38233 HIGH 7.5 microsoft windows_10_1607 Windows Networking Denial of Service Vulnerability 2.4% —
CVE-2022-33654 MED 4.9 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 2.4% —
CVE-2022-31665 HIGH 7.2 vmware identity_manager VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution. 2.4% —
CVE-2022-28256 MED 5.5 adobe acrobat Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to b 2.4% —
CVE-2022-26784 MED 6.5 microsoft windows_server_2012 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability 2.4% —
CVE-2022-24538 MED 6.5 microsoft windows_server_2012 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability 2.4% —
CVE-2021-43899 CRIT 9.8 microsoft wireless_display_adapter_firmware Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability 2.4% —
CVE-2017-9790 HIGH 7.5 apache mesos When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev crashes if the request path is empty, because the parser assumes the request path always starts with ' 2.4% —
CVE-2015-2062 HIGH 7.2 huge-it huge-it_slider Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remote administrators to execute arbitrary SQL commands via the removeslide parameter in a popup_posts or edit_cat action in the sliders_huge_it 2.4% —
CVE-2014-2106 HIGH 7.8 cisco ios Cisco IOS 15.3M before 15.3(3)M2 and IOS XE 3.10.xS before 3.10.2S allow remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCug45898. 2.4% —
CVE-2021-32567 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. 2.4% —
CVE-2020-24427 LOW 3.3 adobe acrobat Acrobat Reader versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an input validation vulnerability when decoding a crafted codec that could result in the disclosure of sensitive memory. An atta 2.4% —
CVE-2019-19770 HIGH 8.2 linux linux_kernel In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_creat 2.4% —
CVE-2024-43521 HIGH 7.5 microsoft windows_server_2012 Windows Hyper-V Denial of Service Vulnerability 2.4% —
CVE-2021-34492 HIGH 8.1 microsoft windows_10 Windows Certificate Spoofing Vulnerability 2.4% —
CVE-2018-19444 HIGH 7.8 foxitsoftware foxit_pdf_sdk_activex A use after free in the TextBox field Validate action in IReader_ContentProvider can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031. An attacker can leverage this to gain remote code execution. Relative to CVE-2018- 2.4% —
CVE-2017-7687 HIGH 7.5 apache mesos When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev might crash because the code accidentally calls inappropriate function. A malicious act 2.4% —
CVE-2007-3756 MED 4.3 apple safari Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to obtain sensitive information via a crafted web page that identifies the URL of the parent window, even when the parent 2.4% —