58.645 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.645 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-0572 | HIGH 7.1 | cisco digital_media_manager Cisco Digital Media Manager (DMM) before 5.2 allows remote authenticated users to discover Cisco Digital Media Player credentials via vectors related to reading a (1) error log or (2) stack trace, aka Bug ID CSCtc46050. | 2.5% | — |
| CVE-2009-4118 | LOW 2.1 | cisco vpn_client The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service (servic | 2.5% | — |
| CVE-2018-0416 | MED 5.3 | cisco wireless_lan_controller_software A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due to incomplete i | 2.5% | — |
| CVE-2018-0295 | HIGH 7.5 | cisco nx-os A vulnerability in the Border Gateway Protocol (BGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the device unexpectedly reloading. The vulnerability is due to incom | 2.5% | — |
| CVE-2008-3281 | MED 6.5 | apple iphone_os libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document. | 2.5% | — |
| CVE-2020-1565 | HIGH 7.5 | microsoft windows_10 An elevation of privilege vulnerability exists when the "Public Account Pictures" folder improperly handles junctions. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a sp | 2.5% | — |
| CVE-2020-1477 | HIGH 7.0 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri | 2.5% | — |
| CVE-2018-0372 | HIGH 7.5 | cisco nx-os A vulnerability in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application-Centric Infrastructure (ACI) Mode could allow an unauthenticated, remote attacker to cause the device to run low on system memory, which could result in a Denia | 2.5% | — |
| CVE-2018-0316 | HIGH 7.5 | cisco ip_phone_firmware A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 6800, 7800, and 8800 Series Phones with Multiplatform Firmware could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpecte | 2.5% | — |
| CVE-2011-1604 | HIGH 7.1 | cisco unified_communications_manager Memory leak in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (memory consumption and process | 2.5% | — |
| CVE-2009-0635 | HIGH 7.1 | cisco ios Memory leak in the Cisco Tunneling Control Protocol (cTCP) encapsulation feature in Cisco IOS 12.4, when an Easy VPN (aka EZVPN) server is enabled, allows remote attackers to cause a denial of service (memory consumption and device crash) via a sequence of TCP | 2.5% | — |
| CVE-2009-0633 | HIGH 7.1 | cisco cisco_ios Multiple unspecified vulnerabilities in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via MIPv6 packets, aka Bug | 2.5% | — |
| CVE-2008-1159 | HIGH 7.1 | cisco ios_s Multiple unspecified vulnerabilities in the SSH server in Cisco IOS 12.4 allow remote attackers to cause a denial of service (device restart) via unknown vectors, aka Bug ID (1) CSCsk42419, (2) CSCsk60020, and (3) CSCsh51293. | 2.5% | — |
| CVE-2006-3146 | MED 5.0 | toshiba bluetooth_stack The TOSRFBD.SYS driver for Toshiba Bluetooth Stack 4.00.29 and earlier on Windows allows remote attackers to cause a denial of service (reboot) via a L2CAP echo request that triggers an out-of-bounds memory access, similar to "Ping o' Death" and as demonstrate | 2.5% | — |
| CVE-2024-22274 | HIGH 7.2 | vmware cloud_foundation The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system. | 2.5% | — |
| CVE-2016-5333 | CRIT 9.8 | vmware photon_os VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key. | 2.5% | — |
| CVE-2023-36910 | CRIT 9.8 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-24081 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Codecs Library Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2019-8240 | HIGH 7.5 | adobe bridge_cc Adobe Bridge CC versions 9.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to information disclosure. | 2.5% | — |
| CVE-2019-8239 | HIGH 7.5 | adobe bridge_cc Adobe Bridge CC versions 9.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to information disclosure. | 2.5% | — |
| CVE-2012-1746 | MED 5.0 | oracle database_server Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, when running on Windows, allows remote attackers to affect availability via unknown vectors, a different vulnerab | 2.5% | — |
| CVE-2018-14617 | MED 5.5 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference and panic in hfsplus_lookup() in fs/hfsplus/dir.c when opening a file (that is purportedly a hard link) in an hfs+ filesystem that has malformed catalog data, and | 2.5% | — |
| CVE-2023-36585 | HIGH 7.5 | microsoft windows_10_1507 Windows upnphost.dll Denial of Service Vulnerability | 2.5% | — |
| CVE-2021-36008 | LOW 3.3 | adobe illustrator Adobe Illustrator version 25.2.3 (and earlier) is affected by an Use-after-free vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to read arbitrary file system information in the context of the c | 2.5% | — |
| CVE-2019-6982 | MED 5.5 | foxitsoftware 3d An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter an Out-of-Bounds Write and crash during the handling of certain PDF files that embed specifically crafted 3D content, because of | 2.5% | — |