IT
57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.057 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2017-15694 MED 6.5 apache geode When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A malicious user could modify this data in a way that affects the operation of the cl 2.2%
CVE-2015-6399 MED 6.8 cisco integrated_management_controller_supervisor The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authenticated users to cause a denial of service (IP interface outage) via crafted parameters in an HTTP request, aka Bug ID CSCuv38286. 2.2%
CVE-2004-0717 HIGH 7.5 opera opera_browser Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability. 2.2%
CVE-2023-36893 MED 6.5 microsoft 365_apps Microsoft Outlook Spoofing Vulnerability 2.2%
CVE-2018-1284 LOW 3.7 apache hive In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the content of a file on the machine running HiveServer2 owned by HiveSer 2.2%
CVE-2017-5654 HIGH 7.5 apache ambari In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Ambari server executes. 2.2%
CVE-2017-3809 MED 5.8 cisco secure_firewall_management_center A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to prevent deployment of a complete and accurate rule base. More Information: CSCvb95281. Known Affected Releases: 6. 2.2%
CVE-2026-11645 HIGH 8.8 google chrome Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 2.2%
CVE-2025-27479 HIGH 7.5 microsoft windows_server_2012 Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network. 2.2%
CVE-2025-27473 HIGH 7.5 microsoft windows_10_1507 Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. 2.2%
CVE-2025-26641 HIGH 7.5 microsoft windows_10_1507 Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. 2.2%
CVE-2021-1712 HIGH 8.0 microsoft sharepoint_enterprise_server Microsoft SharePoint Elevation of Privilege Vulnerability 2.2%
CVE-2018-4360 HIGH 8.8 apple icloud Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7. 2.2%
CVE-2014-3276 MED 4.0 cisco identity_services_engine_software Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial of service 2.2%
CVE-2018-3182 MED 6.5 netapp oncommand_insight Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to co 2.2%
CVE-2018-3137 MED 6.5 netapp oncommand_insight Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols 2.2%
CVE-2016-6493 CRIT 9.8 citrix xenapp Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to memory permission. 2.2%
CVE-2017-7671 HIGH 7.5 apache traffic_server There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump. 2.2%
CVE-2022-47937 CRIT 9.8 apache sling_commons_json Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymo 2.2%
CVE-2021-27266 LOW 3.3 foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio 2.2%
CVE-2021-27264 LOW 3.3 foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio 2.2%
CVE-2014-6602 MED 6.6 microsoft nokia_asha_501 Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows physically proximate attackers to bypass the lock-screen protection mechanism, and read or modify contact information or dial arbitrary telephone numbers, by tapping the SOS Option an 2.2%
CVE-2007-3794 HIGH 10.0 hitachi cosminexus_application_server Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and third-party products that use this software, allows attackers to have an unknown impact via certain GIF images, related t 2.2%
CVE-2019-1740 HIGH 8.6 cisco ios A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability are due to a parsing issue on 2.2%
CVE-2018-0869 MED 5.4 microsoft sharepoint_enterprise_server SharePoint Server 2016 allows an elevation of privilege vulnerability due to how web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". 2.2%