58.646 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.646 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1067 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an | 2.5% | — |
| CVE-2010-1570 | HIGH 7.8 | cisco customer_response_solution The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), 6.0 before 6.0(1)SR1, and 5.0 before 5.0(2)SR3 allows remote attackers to cause a denial of service (CTI server and Node M | 2.5% | — |
| CVE-2009-2871 | HIGH 7.8 | cisco ios Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when SSLVPN sessions, SSH sessions, or IKE encrypted nonces are enabled, allows remote attackers to cause a denial of service (device reload) via a crafted encrypted packet, aka Bug ID CSCsq24002. | 2.5% | — |
| CVE-2009-2870 | HIGH 7.8 | cisco ios Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when the Cisco Unified Border Element feature is enabled, allows remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCsx25880. | 2.5% | — |
| CVE-2022-26816 | MED 6.5 | microsoft windows_server_2016 Windows DNS Server Information Disclosure Vulnerability | 2.5% | — |
| CVE-2021-24075 | MED 6.8 | microsoft windows_10 Microsoft Windows VMSwitch Denial of Service Vulnerability | 2.5% | — |
| CVE-2020-19316 | HIGH 8.8 | laravel framework OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17. | 2.5% | — |
| CVE-2010-4526 | HIGH 7.1 | linux linux_kernel Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a socket that is already locked by a user, | 2.5% | — |
| CVE-2023-38432 | CRIT 9.1 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read. | 2.5% | — |
| CVE-2021-1312 | MED 5.3 | cisco elastic_services_controller A vulnerability in the system resource management of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) to the health monitor API on an affected device. The vulnerability is due to inadequ | 2.5% | — |
| CVE-2019-13050 | HIGH 7.5 | f5 traffix_signaling_delivery_controller Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may | 2.5% | — |
| CVE-2024-30083 | HIGH 7.5 | microsoft windows_server_2012 Windows Standards-Based Storage Management Service Denial of Service Vulnerability | 2.5% | — |
| CVE-2020-10933 | MED 5.3 | debian debian_linux An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the requested size, but no data is copied. Thus, th | 2.5% | — |
| CVE-2018-3932 | HIGH 8.8 | antennahouse office_server_document_converter An exploitable stack-based buffer overflow exists in the Microsoft Word document conversion functionality of the Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312). A crafted Microsoft Word (DOC) document can lead t | 2.5% | — |
| CVE-2009-2867 | HIGH 7.8 | cisco ios Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4T, 12.4XZ, and 12.4YA, when Zone-Based Policy Firewall SIP Inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted SIP transit pack | 2.5% | — |
| CVE-2021-36372 | CRIT 9.8 | apache ozone In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to the key. Authenticated users may use them even after access is revoked. | 2.5% | — |
| CVE-2021-31980 | HIGH 8.1 | microsoft intune_management_extension Microsoft Intune Management Extension Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2022-21977 | LOW 3.3 | microsoft windows_10 Media Foundation Information Disclosure Vulnerability | 2.5% | — |
| CVE-2025-29810 | HIGH 7.5 | microsoft windows_10_1507 Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. | 2.5% | — |
| CVE-2019-7049 | MED 6.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.5% | — |
| CVE-2008-2058 | HIGH 7.8 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.2.x before 7.2(3)2 and 8.0.x before 8.0(2)17 allows remote attackers to cause a denial of service (device reload) via a port scan against TCP port 443 on the device. | 2.5% | — |
| CVE-2018-1289 | HIGH 8.8 | apache fineract In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' and 'sortOrder' which are appended directly with SQL statem | 2.5% | — |
| CVE-2021-31967 | HIGH 7.8 | microsoft vp9_video_extensions VP9 Video Extensions Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2020-2030 | HIGH 7.2 | paloaltonetworks pan-os An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; and all versions of PAN- | 2.5% | — |
| CVE-2014-9748 | HIGH 8.1 | libuv libuv The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv before 1.7.4 does not properly prevent threads from releasing the locks of other threads, which allows attackers to cause a denial of service (deadlock) or possibly have unspecifie | 2.5% | — |