IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.650 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2013-2757 HIGH 7.5 citrix cloudplatform Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C does not properly restrict access to VNC ports on the management network, which allows remote attackers to have unspecified impact via unknown vectors. 2.7% —
CVE-2024-26215 HIGH 7.5 microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability 2.7% —
CVE-2022-40664 CRIT 9.8 apache shiro Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher. 2.7% —
CVE-2021-1385 MED 6.5 cisco ios A vulnerability in the Cisco IOx application hosting environment of multiple Cisco platforms could allow an authenticated, remote attacker to conduct directory traversal attacks and read and write files on the underlying operating system or host system. This v 2.7% —
CVE-2012-2945 HIGH 7.5 apache hadoop Hadoop 1.0.3 contains a symlink vulnerability. 2.7% —
CVE-2020-9482 MED 6.5 apache nifi_registry If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be use 2.7% —
CVE-2018-4201 HIGH 8.8 apple icloud An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affec 2.7% —
CVE-2018-20243 HIGH 7.5 apache fineract The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629. 2.7% —
CVE-2025-59194 HIGH 7.0 microsoft windows_11_22h2 Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally. 2.7% —
CVE-2023-23382 MED 6.5 microsoft azure_machine_learning Azure Machine Learning Compute Instance Information Disclosure Vulnerability 2.7% —
CVE-2022-30189 MED 6.5 microsoft windows_10 Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability 2.7% —
CVE-2020-24415 HIGH 7.8 adobe illustrator Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability require 2.7% —
CVE-2015-8022 HIGH 7.5 f5 big-ip_access_policy_manager The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, an 2.7% —
CVE-2010-0567 MED 5.0 cisco asa_5500 Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.1), 8.1 before 8.1(2.37), and 8.2 before 8.2(1.15); and Cisco PIX 500 Series Security Appliance; allows remote attackers 2.7% —
CVE-2025-47178 HIGH 8.0 microsoft configuration_manager_2503 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network. 2.7% —
CVE-2011-0154 MED 5.1 apple itunes WebKit, as used in Apple iTunes before 10.2 on Windows and Apple iOS, does not properly implement the .sort function for JavaScript arrays, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and a 2.7% —
CVE-2023-29332 HIGH 7.5 microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 2.7% —
CVE-2021-27062 HIGH 7.8 microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability 2.7% —
CVE-2021-27051 HIGH 7.8 microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability 2.7% —
CVE-2021-27050 HIGH 7.8 microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability 2.7% —
CVE-2021-27049 HIGH 7.8 microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability 2.7% —
CVE-2021-27048 HIGH 7.8 microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability 2.7% —
CVE-2021-24108 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 2.7% —
CVE-2020-1952 CRIT 9.8 apache iotdb An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely. 2.7% —
CVE-2020-9616 MED 5.5 adobe premiere_pro Adobe Premiere Pro versions 14.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. 2.7% —