57.061 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.061 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-0677 | HIGH 7.8 | cisco adaptive_security_appliance_software The XML parser in Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.28), 8.6 before 8.6(1.17), 9.0 before 9.0(4.33), 9.1 before 9.1(6), 9.2 before 9.2(3.4), and 9.3 before 9.3(3), when Clientless SSL VPN, AnyConnect SSL VPN, or AnyConnect IKEv2 | 1.9% | — |
| CVE-2024-30017 | HIGH 8.8 | microsoft windows_10_1507 Windows Hyper-V Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2018-1000204 | MED 5.3 | canonical ubuntu_linux Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV and an empty 6-byte cmdp. This may lead to copying up to 1000 kernel heap pages to the userspace. This has been fixed upstream in https://gi | 1.9% | — |
| CVE-2023-29247 | MED 5.4 | apache airflow Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0. | 1.9% | — |
| CVE-2020-3223 | MED 4.9 | cisco ios_xe A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to read arbitrary files on the underlying filesystem of the device. The vulnerability is due to insuf | 1.9% | — |
| CVE-2020-2015 | HIGH 8.8 | paloaltonetworks pan-os A buffer overflow vulnerability in the PAN-OS management server allows authenticated users to crash system processes or potentially execute arbitrary code with root privileges. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions ea | 1.9% | — |
| CVE-2020-13940 | MED 5.5 | apache nifi In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make exte | 1.9% | — |
| CVE-2018-4161 | HIGH 8.8 | apple icloud An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. | 1.9% | — |
| CVE-2015-1050 | MED 4.3 | f5 big-ip_application_security_manager Cross-site scripting (XSS) vulnerability in F5 BIG-IP Application Security Manager (ASM) before 11.6 allows remote attackers to inject arbitrary web script or HTML via the Response Body field when creating a new user account. | 1.9% | — |
| CVE-2015-0640 | HIGH 7.8 | cisco ios_xe The high-speed logging (HSL) feature in Cisco IOS XE 2.x and 3.x before 3.10.4S, 3.11 before 3.11.3S, 3.12 before 3.12.1S, 3.13 before 3.13.0S, 3.14 before 3.14.0S, and 3.15 before 3.15.0S allows remote attackers to cause a denial of service (device reload) vi | 1.9% | — |
| CVE-2015-0637 | HIGH 7.8 | cisco ios The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (device reload) via spoofed AN messages, aka | 1.9% | — |
| CVE-2013-4688 | HIGH 7.8 | juniper junos flowd in Juniper Junos 10.4 before 10.4R11 on SRX devices, when the MSRPC Application Layer Gateway (ALG) is enabled, allows remote attackers to cause a denial of service (daemon crash) via crafted MSRPC requests, aka PR 772834. | 1.9% | — |
| CVE-2012-1472 | MED 6.4 | vmware vcenter_chargeback_manager VMware vCenter Chargeback Manager (aka CBM) before 2.0.1 does not properly handle XML API requests, which allows remote attackers to read arbitrary files or cause a denial of service via unspecified vectors. | 1.9% | — |
| CVE-2025-52434 | HIGH 7.5 | apache tomcat Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue aff | 1.9% | — |
| CVE-2025-21307 | CRIT 9.8 | microsoft windows_10_1507 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2020-9611 | MED 5.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a stack exhaustion vulnerability. Successful exploitation could lead to application denial-of-service. | 1.9% | — |
| CVE-2020-17414 | HIGH 7.8 | foxitsoftware foxit_reader This vulnerability allows local attackers to escalate privileges on affected installations of Foxit Reader 10.0.0.35798. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The s | 1.9% | — |
| CVE-2016-9680 | HIGH 7.5 | citrix provisioning_services Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors. | 1.9% | — |
| CVE-2026-64901 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.9% | — |
| CVE-2025-21224 | HIGH 8.1 | microsoft windows_10_21h2 Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2023-36763 | HIGH 7.5 | microsoft 365_apps Microsoft Outlook Information Disclosure Vulnerability | 1.9% | — |
| CVE-2022-34714 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2021-41350 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 1.9% | — |
| CVE-2016-4769 | HIGH 8.8 | apple itunes WebKit in Apple iTunes before 12.5.1 on Windows and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | 1.9% | — |
| CVE-2015-7752 | HIGH 7.8 | juniper junos The SSH server in Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D10, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D35, 13.3 before 13.3R6, 14.1 before 14.1R5, 14.1X53 befo | 1.9% | — |