58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-30153 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2017-9458 | CRIT 9.8 | paloaltonetworks pan-os XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive inform | 2.5% | — |
| CVE-2021-40114 | MED 6.8 | cisco secure_firewall_management_center Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is d | 2.5% | — |
| CVE-2020-5015 | HIGH 7.5 | ibm elastic_storage_server IBM Elastic Storage System 6.0.0 through 6.0.1.2 and IBM Elastic Storage Server 5.3.0 through 5.3.6.2 could allow a remote attacker to cause a denial of service by sending malformed UDP requests. IBM X-Force ID: 193486. | 2.5% | — |
| CVE-2022-41042 | HIGH 7.4 | microsoft visual_studio_code Visual Studio Code Information Disclosure Vulnerability | 2.5% | — |
| CVE-2021-40465 | HIGH 7.8 | microsoft windows_10 Windows Text Shaping Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-36161 | CRIT 9.8 | apache dubbo Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean with special toString method. In the latest version, we fix the toString call in timeout, cache and some other | 2.5% | — |
| CVE-2013-6357 | MED 6.8 | apache tomcat Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as de | 2.5% | — |
| CVE-2013-0682 | HIGH 7.5 | cogentdatahub cascade_datahub Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 do not properly handle exceptions, which allows remote attackers to cause a denial of service (applic | 2.5% | — |
| CVE-2013-0149 | MED 5.8 | cisco asa_5500 The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before perf | 2.5% | — |
| CVE-2024-28752 | CRIT 9.3 | apache cxf A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the d | 2.5% | — |
| CVE-2023-21585 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabi | 2.5% | — |
| CVE-2021-34492 | HIGH 8.1 | microsoft windows_10 Windows Certificate Spoofing Vulnerability | 2.5% | — |
| CVE-2018-13099 | MED 5.5 | canonical ubuntu_linux An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (out-of-bounds memory access and BUG) can occur for a modified f2fs filesystem image in which an inline inode contains an invalid reserved blkaddr. | 2.5% | — |
| CVE-2023-21606 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitat | 2.5% | — |
| CVE-2021-42276 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2019-1572 | HIGH 7.5 | paloaltonetworks pan-os PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files. | 2.5% | — |
| CVE-2017-15693 | HIGH 7.5 | apache geode In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objects to be deserialized. A user with DATA:WRITE access to the cluster may be able to cause remote code | 2.5% | — |
| CVE-2026-43284 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter( | 2.5% | — |
| CVE-2020-9641 | HIGH 7.8 | adobe illustrator Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution . | 2.5% | — |
| CVE-2018-8323 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.5% | — |
| CVE-2018-8299 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.5% | — |
| CVE-2013-3080 | HIGH 9.0 | vmware vcenter_server_appliance VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to create or overwrite arbitrary files, and consequently execute arbitrary code or cause a denial of service, by leveraging Virtual Appliance Management Interface (VAM | 2.5% | — |
| CVE-2009-2863 | HIGH 7.1 | cisco ios Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227. | 2.5% | — |
| CVE-2021-34489 | HIGH 7.8 | microsoft windows_10 DirectWrite Remote Code Execution Vulnerability | 2.5% | — |