IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.650 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2014-0658 MED 5.4 cisco unified_ip_phone_9951 Cisco 9900 Unified IP phones allow remote attackers to cause a denial of service (unregistration) via a crafted SIP header, aka Bug ID CSCul24898. 2.7% —
CVE-2022-26903 HIGH 7.8 microsoft excel Windows Graphics Component Remote Code Execution Vulnerability 2.7% —
CVE-2017-0303 HIGH 7.5 f5 big-ip_access_policy_manager In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2 and 11.5.1 to 11.6.1, under limited circumstances connections handled by a Virtual Server with an associated SOCKS profile may 2.7% —
CVE-2016-4925 HIGH 7.5 juniper junose Receipt of a specifically malformed IPv6 packet processed by the router may trigger a line card reset: processor exception 0x68616c74 (halt) in task: scheduler. The line card will reboot and recover without user interaction. However, additional specifically ma 2.7% —
CVE-2015-1455 HIGH 7.5 fortinet fortiauthenticator Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it easier for remote attackers to obtain access via unspecified vectors. 2.7% —
CVE-2021-42524 HIGH 7.8 adobe animate Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a 2.7% —
CVE-2021-42272 HIGH 7.8 adobe animate Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a 2.7% —
CVE-2020-1198 HIGH 7.4 microsoft sharepoint_enterprise_server <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially 2.7% —
CVE-2020-24557 HIGH 7.8 trendmicro apex_one A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege e 2.7%
CVE-2017-7663 MED 6.1 apache openmeetings Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0. 2.7% —
CVE-2024-38226 HIGH 7.3 microsoft office_2019 Microsoft Publisher Security Feature Bypass Vulnerability 2.7%
CVE-2010-1763 HIGH 10.0 apple itunes Unspecified vulnerability in WebKit in Apple iTunes before 9.2 on Windows has unknown impact and attack vectors, a different vulnerability than CVE-2010-1387 and CVE-2010-1769. 2.7% —
CVE-2022-28890 CRIT 9.8 apache jena A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities. 2.7% —
CVE-2021-34439 HIGH 7.8 microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 2.7% —
CVE-2019-0555 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows Server 2.7% —
CVE-2011-1573 MED 5.9 linux linux_kernel net/sctp/sm_make_chunk.c in the Linux kernel before 2.6.34, when addip_enable and auth_enable are used, does not consider the amount of zero padding during calculation of chunk lengths for (1) INIT and (2) INIT ACK chunks, which allows remote attackers to caus 2.7% —
CVE-2008-3792 HIGH 7.1 linux linux_kernel net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4 does not verify that the SCTP-AUTH extension is enabled before proceeding with SCTP-AUTH API functions, which allows attackers to cause a de 2.7% —
CVE-2011-4087 HIGH 7.5 linux linux_kernel The br_parse_ip_options function in net/bridge/br_netfilter.c in the Linux kernel before 2.6.39 does not properly initialize a certain data structure, which allows remote attackers to cause a denial of service by leveraging connectivity to a network interface 2.7% —
CVE-2022-35838 HIGH 7.5 microsoft windows_11 HTTP V3 Denial of Service Vulnerability 2.7% —
CVE-2022-24532 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2.7% —
CVE-2018-5224 HIGH 8.8 atlassian bamboo Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan in Bamboo that h 2.7% —
CVE-2018-0170 HIGH 7.5 cisco ios_xe A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition, related to the OpenDNS software. The vulnerability is due to a logic error that exi 2.7% —
CVE-2018-0157 HIGH 8.6 cisco ios_xe A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a device to reload. The vulnerability is due to the way fragmented packets are handled in the firewall code. An attacker could exp 2.7% —
CVE-2018-0136 HIGH 8.6 cisco ios_xr A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (ASR) 9000 Series could allow an unauthenticated, remote attacker to trigger a reload of one or more Trident-based line cards, resulting in a 2.7% —
CVE-2017-3864 HIGH 8.6 cisco ios A vulnerability in the DHCP client implementation of Cisco IOS (12.2, 12.4, and 15.0 through 15.6) and Cisco IOS XE (3.3 through 3.7) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability occurs during 2.7% —