57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-32565 | HIGH 7.5 | apache traffic_server Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. | 2.1% | — |
| CVE-2018-8221 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server | 2.1% | — |
| CVE-2018-8217 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server | 2.1% | — |
| CVE-2018-8216 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server | 2.1% | — |
| CVE-2018-8215 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server | 2.1% | — |
| CVE-2018-8211 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows 10 Serv | 2.1% | — |
| CVE-2016-7259 | HIGH 7.8 | microsoft windows_10 The Graphics Component in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows l | 2.1% | — |
| CVE-2024-30042 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2024-26204 | HIGH 7.5 | microsoft outlook Outlook for Android Information Disclosure Vulnerability | 2.1% | — |
| CVE-2022-26477 | HIGH 7.5 | apache systemds The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered with, may lead to CPU exhaustion. As a fix, we added an upper bound and termination condition in the read and wri | 2.1% | — |
| CVE-2010-4312 | MED 6.4 | apache tomcat The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie. | 2.1% | — |
| CVE-2022-38398 | MED 5.3 | apache batik Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14. | 2.1% | — |
| CVE-2020-2041 | HIGH 7.5 | paloaltonetworks pan-os An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to send a specifically crafted request to the device that causes the appweb service to crash. Repeated attempts to send this request result in | 2.1% | — |
| CVE-2020-1323 | MED 6.1 | microsoft sharepoint_enterprise_server An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulner | 2.1% | — |
| CVE-2017-6663 | MED 6.5 | cisco ios A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. Mo | 2.1% | |
| CVE-2011-1026 | MED 6.8 | apache archiva Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hijack the authentication of administrators. | 2.1% | — |
| CVE-2009-2452 | HIGH 10.0 | citrix licensing Multiple unspecified vulnerabilities in Citrix Licensing 11.5 have unknown impact and attack vectors, related to "underlying components of the License Management Console." | 2.1% | — |
| CVE-2007-4724 | MED 4.3 | apache tomcat Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters. | 2.1% | — |
| CVE-2025-23184 | MED 5.9 | apache cxf A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies t | 2.1% | — |
| CVE-2023-27522 | HIGH 7.5 | apache http_server HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. | 2.1% | — |
| CVE-2022-33658 | MED 4.9 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2022-33652 | MED 4.9 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2022-21968 | MED 4.3 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Security Feature Bypass Vulnerability | 2.1% | — |
| CVE-2023-36697 | MED 6.8 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2017-12328 | MED 5.8 | cisco ip_phone_8800_series_firmware A vulnerability in Session Initiation Protocol (SIP) call handling in Cisco IP Phone 8800 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the SIP process unexpectedly restarts. All active phon | 2.1% | — |