IT
58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.639 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2016-6407 HIGH 7.5 cisco web_security_appliance Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (link saturation) by making many HTTP requests for overlapping byte ranges simultaneously, aka Bug ID CSCuz27219. 2.5% —
CVE-2015-4223 MED 5.0 cisco ios_xr Cisco IOS XR 5.1.3 allows remote attackers to cause a denial of service (process reload) via crafted MPLS Label Distribution Protocol (LDP) packets, aka Bug ID CSCuu77478. 2.5% —
CVE-2022-26910 MED 5.3 microsoft skype_for_business_server Skype for Business and Lync Spoofing Vulnerability 2.5% —
CVE-2018-17186 HIGH 7.2 apache syncope An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution. 2.5% —
CVE-2017-2315 HIGH 7.5 juniper junos On Juniper Networks EX Series Ethernet Switches running affected Junos OS versions, a vulnerability in IPv6 processing has been discovered that may allow a specially crafted IPv6 Neighbor Discovery (ND) packet destined to an EX Series Ethernet Switch to cause 2.5% —
CVE-2018-14613 MED 5.5 linux linux_kernel An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in io_ctl_map_page() when mounting and operating a crafted btrfs image, because of a lack of block group item validation in check_leaf_item in fs/btrfs/tree-ch 2.5% —
CVE-2018-14610 MED 5.5 linux linux_kernel An issue was discovered in the Linux kernel through 4.17.10. There is out-of-bounds access in write_extent_buffer() when mounting and operating a crafted btrfs image, because of a lack of verification that each block group has a corresponding chunk at mount ti 2.5% —
CVE-2017-3876 HIGH 7.5 cisco ios_xr A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to improper handling of gRPC req 2.5% —
CVE-2017-3859 HIGH 7.5 cisco ios_xe A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a format string vul 2.5% —
CVE-2017-3856 HIGH 7.5 cisco ios_xe A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to insufficient resource handling by the affected software when the web u 2.5% —
CVE-2017-3808 HIGH 7.5 cisco unified_communications_manager A vulnerability in the Session Initiation Protocol (SIP) UDP throttling process of Cisco Unified Communications Manager (Cisco Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The v 2.5% —
CVE-2000-0487 LOW 3.6 microsoft windows_2000 The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability. 2.5% —
CVE-2025-27469 HIGH 7.5 microsoft windows_10_1507 Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. 2.5% —
CVE-2024-38073 HIGH 7.5 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Denial of Service Vulnerability 2.5% —
CVE-2024-21755 HIGH 8.8 fortinet fortisandbox A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized 2.5% —
CVE-2021-24070 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 2.5% —
CVE-2021-24068 HIGH 7.8 microsoft excel Microsoft Excel Remote Code Execution Vulnerability 2.5% —
CVE-2021-24067 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 2.5% —
CVE-2020-3586 CRIT 9.4 cisco dna_spaces\ A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient validation of user-supplied input 2.5% —
CVE-2007-3945 MED 6.4 rsbac rule_set_based_access_control Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Managem 2.5% —
CVE-2026-62392 CRIT 9.8 apache kylin Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recom 2.5% —
CVE-2025-59237 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 2.5% —
CVE-2022-25757 CRIT 9.8 apache apisix In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSON with a duplicate key, the attacker can bypass the body_schema validation in the request-validation plugin. Fo 2.5% —
CVE-2012-0287 LOW 2.6 wordpress wordpress Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handl 2.5% —
CVE-2021-31200 HIGH 7.2 microsoft neural_network_intelligence Common Utilities Remote Code Execution Vulnerability 2.5% —