58.650 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2004-0714 | MED 5.0 | cisco ios Cisco Internetwork Operating System (IOS) 12.0S through 12.3T attempts to process SNMP solicited operations on improper ports (UDP 162 and a randomly chosen UDP port), which allows remote attackers to cause a denial of service (device reload and memory corrupt | 2.6% | — |
| CVE-2021-44714 | LOW 2.5 | adobe acrobat Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a Violation of Secure Design Principles that could lead to a Security feature bypass. Acrobat Reader DC displays a warning message w | 2.6% | — |
| CVE-2015-0597 | MED 5.0 | cisco webex_meetings_server The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via crafted packets, aka Bug IDs CSCuj67166 and CSCuj67159. | 2.6% | — |
| CVE-2014-6478 | MED 4.3 | juniper junos_space Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect integrity via vectors related to SERVER:SSL:yaSSL. | 2.6% | — |
| CVE-2009-0614 | HIGH 9.0 | cisco unified_meetingplace_web_conferencing Unspecified vulnerability in the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0 before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) (aka 7.0 MR1) allows remote attackers to bypass authentication and obtain administrative access via a crafted U | 2.6% | — |
| CVE-2007-4295 | MED 6.8 | cisco ios Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows remote attackers to execute arbitrary code via a malformed SIP packet, aka CSCsi80749. | 2.6% | — |
| CVE-2007-4294 | MED 6.8 | cisco unified_communications_manager Unspecified vulnerability in Cisco Unified Communications Manager (CUCM) 5.0, 5.1, and 6.0, and IOS 12.0 through 12.4, allows remote attackers to execute arbitrary code via a malformed SIP packet, aka CSCsi80102. | 2.6% | — |
| CVE-2021-31958 | HIGH 7.5 | microsoft windows_10 Windows NTLM Elevation of Privilege Vulnerability | 2.6% | — |
| CVE-2015-4208 | HIGH 7.5 | cisco webex_meeting_center Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive information or conduct SQL injection attacks via vectors involving read access to a request, aka Bug ID CSCup88398. | 2.6% | — |
| CVE-2015-3192 | MED 5.5 | fedoraproject fedora Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafte | 2.6% | — |
| CVE-2014-3317 | MED 5.5 | cisco unified_communications_manager Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager 10.0(1) allows remote authenticated users to delete arbitrary files via a crafted URL, aka Bug ID CSCup76314. | 2.6% | — |
| CVE-2025-54101 | MED 4.8 | microsoft windows_10_1507 Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network. | 2.6% | — |
| CVE-2022-30171 | MED 5.5 | microsoft office_online_server Microsoft Office Information Disclosure Vulnerability | 2.6% | — |
| CVE-2018-8207 | MED 4.7 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 2.6% | — |
| CVE-2017-11823 | MED 6.7 | microsoft windows_10 The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it handles Windows PowerShell sessions, aka "Microsoft Windows Security Feature Bypass". | 2.6% | — |
| CVE-2014-7807 | MED 5.0 | apache cloudstack Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind. | 2.6% | — |
| CVE-2011-3279 | HIGH 7.8 | cisco ios The provider-edge MPLS NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) via a malformed SIP packet to UDP port 5060, aka Bug ID CSCti98219. | 2.6% | — |
| CVE-2021-43882 | CRIT 9.0 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2021-27738 | HIGH 7.5 | apache kylin All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any security checks, which allowed an unauthenticated user to issue arbitrary requests, such as assigning/unassigning | 2.6% | — |
| CVE-2018-14612 | MED 5.5 | linux linux_kernel An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in btrfs_root_node() when mounting a crafted btrfs image, because of a lack of chunk block group mapping validation in btrfs_read_block_groups in fs/btrfs/exte | 2.6% | — |
| CVE-2017-5053 | CRIT 9.6 | google chrome An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to Array.prototype.indexOf. | 2.6% | — |
| CVE-2007-2398 | HIGH 7.1 | apple safari Apple Safari 3.0.1 beta (522.12.12) on Windows allows remote attackers to modify the window title and address bar while filling the main window with arbitrary content by setting the location bar and using setTimeout() to create an event that modifies the windo | 2.6% | — |
| CVE-2022-22942 | HIGH 7.8 | vmware photon_os The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer. | 2.6% | — |
| CVE-2020-1158 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerabilit | 2.6% | — |
| CVE-2020-1157 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerabilit | 2.6% | — |