57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2009-5040 | MED 6.8 | cisco ios CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555. | 2.0% | — |
| CVE-2022-24460 | HIGH 7.0 | microsoft windows_10 Tablet Windows User Interface Application Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2021-43016 | MED 5.5 | adobe incopy Adobe InCopy version 16.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of t | 2.0% | — |
| CVE-2010-0139 | HIGH 9.0 | cisco unified_meetingplace Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in a database via unspecified vectors, aka Bug ID CSCtc39691. | 2.0% | — |
| CVE-2024-43609 | MED 6.5 | microsoft 365_apps Microsoft Office Spoofing Vulnerability | 2.0% | — |
| CVE-2023-36567 | HIGH 7.5 | microsoft windows_10_1507 Windows Deployment Services Information Disclosure Vulnerability | 2.0% | — |
| CVE-2023-29348 | HIGH 7.5 | microsoft windows_server_2008 Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability | 2.0% | — |
| CVE-2023-21757 | HIGH 7.5 | microsoft windows_10 Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability | 2.0% | — |
| CVE-2018-15444 | MED 6.3 | cisco energy_management_suite_software A vulnerability in the web-based user interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper hand | 2.0% | — |
| CVE-2013-5557 | MED 6.3 | cisco adaptive_security_appliance_software The Proxy Bypass Content Rewriter feature in the WebVPN subsystem in Cisco Adaptive Security Appliance (ASA) Software 9.1(.2) and earlier allows remote authenticated users to cause a denial of service (device crash or error-recovery event) via an HTTP request | 2.0% | — |
| CVE-2004-0710 | MED 5.0 | cisco ios IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Series Internet Routers running IOS before 12.2(17b)SXA, before 12.2(17d)SXB, or before 12.2(14)SY03 could allow remote attackers to cause a denial of service (devi | 2.0% | — |
| CVE-2022-37976 | HIGH 8.8 | microsoft windows_server_2008 Active Directory Certificate Services Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2022-30211 | HIGH 7.5 | microsoft windows_10 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-40780 | HIGH 7.8 | adobe media_encoder Adobe Media Encoder version 15.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required t | 2.0% | — |
| CVE-2021-40779 | HIGH 7.8 | adobe media_encoder Adobe Media Encoder version 15.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required t | 2.0% | — |
| CVE-2001-0048 | HIGH 7.2 | microsoft windows_2000 The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Rest | 2.0% | — |
| CVE-2015-0011 | MED 4.7 | microsoft windows_7 mrxdav.sys (aka the WebDAV driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow | 2.0% | — |
| CVE-2010-3985 | MED 4.3 | hp operations_orchestration Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9.0, when Internet Explorer 6.0 is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2.0% | — |
| CVE-2025-47165 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 2.0% | — |
| CVE-2023-30631 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.Thi | 2.0% | — |
| CVE-2021-1224 | MED 5.8 | cisco ios_xe Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due | 2.0% | — |
| CVE-2017-15696 | HIGH 7.5 | apache geode When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode locator to extract configuration data and | 2.0% | — |
| CVE-2015-6340 | MED 5.0 | cisco asr_5000_software The Proxy Mobile IPv6 (PMIPv6) component in the CDMA implementation on Cisco ASR 5000 devices with software 19.0.M0.60737 allows remote attackers to cause a denial of service (hamgr process restart) via a crafted header in a PMIPv6 packet, aka Bug ID CSCuv6328 | 2.0% | — |
| CVE-2015-6332 | MED 5.0 | cisco prime_infrastructure Cisco Prime Infrastructure 2.2 allows remote attackers to cause a denial of service (daemon hang) by sending many SSL renegotiation requests, aka Bug ID CSCuv56830. | 2.0% | — |
| CVE-2013-3402 | MED 6.5 | cisco unified_communications_manager An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary commands via unknown vectors, aka Bug ID CSCuh73440. | 2.0% | — |