IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2016-4921 HIGH 7.5 juniper junos By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all available resources can be consumed, leading to the inability to store next hop information for legitimate traffic. In extreme cases, the crafted IPv6 traffic may r 2.9%
CVE-2023-36560 HIGH 8.8 microsoft .net_framework ASP.NET Security Feature Bypass Vulnerability 2.9%
CVE-2019-12407 MED 6.1 apache jspwiki On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the remember parameter on some of the JSPs, which could allow the attacker to execute javascript in the vict 2.9%
CVE-2019-12404 MED 6.1 apache jspwiki On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp, which could allow the attacker to execute javascript in the victim's browser and get some s 2.9%
CVE-2019-10087 MED 6.1 apache jspwiki On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Page Revision History, which could allow the attacker to execute javascript in the victim's browser and 2.9%
CVE-2018-17187 HIGH 7.4 apache qpid_proton-j The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a verification mode was explicitly configured, client and server modes previously defaulted as documented to not ve 2.9%
CVE-2014-0721 HIGH 10.0 cisco unified_sip_phone_3905 The Cisco Unified SIP Phone 3905 with firmware before 9.4(1) allows remote attackers to obtain root access via a session on the test interface on TCP port 7870, aka Bug ID CSCuh75574. 2.9%
CVE-2021-31205 MED 6.5 microsoft windows_10 Windows SMB Client Security Feature Bypass Vulnerability 2.9%
CVE-2017-15717 MED 6.1 apache sling_xss_protection_api A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected version 2.9%
CVE-2010-4682 HIGH 7.8 cisco 5500_series_adaptive_security_appliance Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote attackers to cause a denial of service (memory consumption) by making multiple incorrect LDAP authentication attempts, aka Bug ID CSCtf29867. 2.9%
CVE-2022-30130 LOW 3.3 microsoft .net_framework .NET Framework Denial of Service Vulnerability 2.9%
CVE-2019-14897 CRIT 9.8 canonical ubuntu_linux A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecti 2.9%
CVE-2020-17082 HIGH 7.8 microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability 2.9%
CVE-2019-0729 CRIT 9.8 microsoft java_software_development_kit An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'. 2.9%
CVE-2018-8112 MED 4.3 microsoft edge A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge. 2.9%
CVE-2022-21925 MED 5.3 microsoft windows_7 Windows BackupKey Remote Protocol Security Feature Bypass Vulnerability 2.9%
CVE-2022-21924 MED 5.3 microsoft windows_10 Workstation Service Remote Protocol Security Feature Bypass Vulnerability 2.9%
CVE-2020-1951 MED 5.5 apache tika A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23. 2.9%
CVE-2012-0031 MED 4.6 apache http_server scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, 2.9%
CVE-2008-4933 HIGH 7.8 linux linux_kernel Buffer overflow in the hfsplus_find_cat function in fs/hfsplus/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfsplus filesystem image with an invalid catalog namelength 2.9%
CVE-2019-0874 MED 6.1 microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'. 2.9%
CVE-2007-5587 MED 6.9 macrovision safedisc Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and 2.9%
CVE-2021-31522 CRIT 9.8 apache kylin Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions. 2.9%
CVE-2018-8015 HIGH 7.5 apache orc In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call in the C++ or Java parser. The impact of this bug is most likely denial-of-service against software that uses the ORC file parser. With the C++ parser, the stack 2.9%
CVE-2008-5537 HIGH 9.3 pctools pctools_antivirus PC Tools AntiVirus 4.4.2.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a 2.9%