58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-0658 | MED 5.4 | cisco unified_ip_phone_9951 Cisco 9900 Unified IP phones allow remote attackers to cause a denial of service (unregistration) via a crafted SIP header, aka Bug ID CSCul24898. | 2.7% | — |
| CVE-2022-26903 | HIGH 7.8 | microsoft excel Windows Graphics Component Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2017-0303 | HIGH 7.5 | f5 big-ip_access_policy_manager In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2 and 11.5.1 to 11.6.1, under limited circumstances connections handled by a Virtual Server with an associated SOCKS profile may | 2.7% | — |
| CVE-2016-4925 | HIGH 7.5 | juniper junose Receipt of a specifically malformed IPv6 packet processed by the router may trigger a line card reset: processor exception 0x68616c74 (halt) in task: scheduler. The line card will reboot and recover without user interaction. However, additional specifically ma | 2.7% | — |
| CVE-2015-1455 | HIGH 7.5 | fortinet fortiauthenticator Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it easier for remote attackers to obtain access via unspecified vectors. | 2.7% | — |
| CVE-2021-42524 | HIGH 7.8 | adobe animate Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a | 2.7% | — |
| CVE-2021-42272 | HIGH 7.8 | adobe animate Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a | 2.7% | — |
| CVE-2020-1198 | HIGH 7.4 | microsoft sharepoint_enterprise_server <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially | 2.7% | — |
| CVE-2020-24557 | HIGH 7.8 | trendmicro apex_one A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege e | 2.7% | |
| CVE-2017-7663 | MED 6.1 | apache openmeetings Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0. | 2.7% | — |
| CVE-2024-38226 | HIGH 7.3 | microsoft office_2019 Microsoft Publisher Security Feature Bypass Vulnerability | 2.7% | |
| CVE-2010-1763 | HIGH 10.0 | apple itunes Unspecified vulnerability in WebKit in Apple iTunes before 9.2 on Windows has unknown impact and attack vectors, a different vulnerability than CVE-2010-1387 and CVE-2010-1769. | 2.7% | — |
| CVE-2022-28890 | CRIT 9.8 | apache jena A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities. | 2.7% | — |
| CVE-2021-34439 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2019-0555 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows Server | 2.7% | — |
| CVE-2011-1573 | MED 5.9 | linux linux_kernel net/sctp/sm_make_chunk.c in the Linux kernel before 2.6.34, when addip_enable and auth_enable are used, does not consider the amount of zero padding during calculation of chunk lengths for (1) INIT and (2) INIT ACK chunks, which allows remote attackers to caus | 2.7% | — |
| CVE-2008-3792 | HIGH 7.1 | linux linux_kernel net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4 does not verify that the SCTP-AUTH extension is enabled before proceeding with SCTP-AUTH API functions, which allows attackers to cause a de | 2.7% | — |
| CVE-2011-4087 | HIGH 7.5 | linux linux_kernel The br_parse_ip_options function in net/bridge/br_netfilter.c in the Linux kernel before 2.6.39 does not properly initialize a certain data structure, which allows remote attackers to cause a denial of service by leveraging connectivity to a network interface | 2.7% | — |
| CVE-2022-35838 | HIGH 7.5 | microsoft windows_11 HTTP V3 Denial of Service Vulnerability | 2.7% | — |
| CVE-2022-24532 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2018-5224 | HIGH 8.8 | atlassian bamboo Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan in Bamboo that h | 2.7% | — |
| CVE-2018-0170 | HIGH 7.5 | cisco ios_xe A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition, related to the OpenDNS software. The vulnerability is due to a logic error that exi | 2.7% | — |
| CVE-2018-0157 | HIGH 8.6 | cisco ios_xe A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a device to reload. The vulnerability is due to the way fragmented packets are handled in the firewall code. An attacker could exp | 2.7% | — |
| CVE-2018-0136 | HIGH 8.6 | cisco ios_xr A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (ASR) 9000 Series could allow an unauthenticated, remote attacker to trigger a reload of one or more Trident-based line cards, resulting in a | 2.7% | — |
| CVE-2017-3864 | HIGH 8.6 | cisco ios A vulnerability in the DHCP client implementation of Cisco IOS (12.2, 12.4, and 15.0 through 15.6) and Cisco IOS XE (3.3 through 3.7) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability occurs during | 2.7% | — |