58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-2757 | HIGH 7.5 | citrix cloudplatform Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C does not properly restrict access to VNC ports on the management network, which allows remote attackers to have unspecified impact via unknown vectors. | 2.7% | — |
| CVE-2024-26215 | HIGH 7.5 | microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability | 2.7% | — |
| CVE-2022-40664 | CRIT 9.8 | apache shiro Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher. | 2.7% | — |
| CVE-2021-1385 | MED 6.5 | cisco ios A vulnerability in the Cisco IOx application hosting environment of multiple Cisco platforms could allow an authenticated, remote attacker to conduct directory traversal attacks and read and write files on the underlying operating system or host system. This v | 2.7% | — |
| CVE-2012-2945 | HIGH 7.5 | apache hadoop Hadoop 1.0.3 contains a symlink vulnerability. | 2.7% | — |
| CVE-2020-9482 | MED 6.5 | apache nifi_registry If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be use | 2.7% | — |
| CVE-2018-4201 | HIGH 8.8 | apple icloud An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affec | 2.7% | — |
| CVE-2018-20243 | HIGH 7.5 | apache fineract The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629. | 2.7% | — |
| CVE-2025-59194 | HIGH 7.0 | microsoft windows_11_22h2 Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally. | 2.7% | — |
| CVE-2023-23382 | MED 6.5 | microsoft azure_machine_learning Azure Machine Learning Compute Instance Information Disclosure Vulnerability | 2.7% | — |
| CVE-2022-30189 | MED 6.5 | microsoft windows_10 Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability | 2.7% | — |
| CVE-2020-24415 | HIGH 7.8 | adobe illustrator Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability require | 2.7% | — |
| CVE-2015-8022 | HIGH 7.5 | f5 big-ip_access_policy_manager The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, an | 2.7% | — |
| CVE-2010-0567 | MED 5.0 | cisco asa_5500 Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.1), 8.1 before 8.1(2.37), and 8.2 before 8.2(1.15); and Cisco PIX 500 Series Security Appliance; allows remote attackers | 2.7% | — |
| CVE-2025-47178 | HIGH 8.0 | microsoft configuration_manager_2503 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network. | 2.7% | — |
| CVE-2011-0154 | MED 5.1 | apple itunes WebKit, as used in Apple iTunes before 10.2 on Windows and Apple iOS, does not properly implement the .sort function for JavaScript arrays, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and a | 2.7% | — |
| CVE-2023-29332 | HIGH 7.5 | microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2021-27062 | HIGH 7.8 | microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-27051 | HIGH 7.8 | microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-27050 | HIGH 7.8 | microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-27049 | HIGH 7.8 | microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-27048 | HIGH 7.8 | microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-24108 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2020-1952 | CRIT 9.8 | apache iotdb An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely. | 2.7% | — |
| CVE-2020-9616 | MED 5.5 | adobe premiere_pro Adobe Premiere Pro versions 14.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.7% | — |