57.075 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.075 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-3460 | MED 6.5 | canonical ubuntu_linux A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1. | 1.8% | — |
| CVE-2019-3459 | MED 6.5 | canonical ubuntu_linux A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1. | 1.8% | — |
| CVE-2023-25692 | HIGH 7.5 | apache apache-airflow-providers-google Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0. | 1.8% | — |
| CVE-2018-0414 | MED 5.7 | cisco secure_access_control_server_solution_engine A vulnerability in the web-based UI of Cisco Secure Access Control Server could allow an authenticated, remote attacker to gain read access to certain information in an affected system. The vulnerability is due to improper handling of XML External Entities (XX | 1.8% | — |
| CVE-2016-9028 | HIGH 8.8 | citrix netscaler_application_delivery_controller_firmware Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header. | 1.8% | — |
| CVE-2008-6820 | HIGH 10.0 | ibm db2 The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856. | 1.8% | — |
| CVE-2007-6045 | HIGH 10.0 | ibm db2_universal_database Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors. | 1.8% | — |
| CVE-2007-5651 | HIGH 7.1 | cisco catos Unspecified vulnerability in the Extensible Authentication Protocol (EAP) implementation in Cisco IOS 12.3 and 12.4 on Cisco Access Points and 1310 Wireless Bridges (Wireless EAP devices), IOS 12.1 and 12.2 on Cisco switches (Wired EAP devices), and CatOS 6.x | 1.8% | — |
| CVE-2025-48734 | HIGH 8.8 | apache commons_beanutils Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However th | 1.8% | — |
| CVE-2025-24035 | HIGH 8.1 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.8% | — |
| CVE-2022-41131 | HIGH 7.8 | apache airflow Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG | 1.8% | — |
| CVE-2022-38221 | CRIT 9.8 | the_isle_evrima_project the_isle_evrima A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 before 2022-08-12 allows a remote attacker to crash any server with an accessible RCON port, or possibly execute arbitrary code. | 1.8% | — |
| CVE-2021-1728 | HIGH 8.8 | microsoft system_center_operations_manager System Center Operations Manager Elevation of Privilege Vulnerability | 1.8% | — |
| CVE-2020-3398 | HIGH 8.6 | cisco nx-os A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a BGP session to repeatedly reset, causing a partial denial of service (DoS) condition due | 1.8% | — |
| CVE-2017-6625 | HIGH 7.1 | cisco secure_firewall_threat_defense A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of Service" vulnerability in the access control policy of Cisco Firepower System Software could allow an authenticated, remote attacker to cause an affected system | 1.8% | — |
| CVE-2014-3263 | MED 5.4 | cisco ios The ScanSafe module in Cisco IOS 15.3(3)M allows remote attackers to cause a denial of service (device reload) via HTTPS packets that require tower processing, aka Bug ID CSCum97038. | 1.8% | — |
| CVE-2019-12678 | HIGH 7.5 | cisco adaptive_security_appliance A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) | 1.8% | — |
| CVE-2019-12659 | HIGH 7.5 | cisco ios_xe A vulnerability in the HTTP server code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the HTTP server to crash. The vulnerability is due to a logical error in the logging mechanism. An attacker could exploit this vulnerabili | 1.8% | — |
| CVE-2019-12656 | HIGH 7.5 | cisco cgr_1000_firmware A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a denial of service (DoS) condition. The vulnerability is | 1.8% | — |
| CVE-2010-1146 | MED 6.9 | linux linux_kernel The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the .reiserfs_priv directory, which allows local users to gain privileges by modifying (1) extended attributes or (2) ACLs, as demonstrated by d | 1.8% | — |
| CVE-2024-38104 | HIGH 8.8 | microsoft windows_10_1507 Windows Fax Service Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2023-35329 | MED 6.5 | microsoft windows_10_1507 Windows Authentication Denial of Service Vulnerability | 1.8% | — |
| CVE-2021-26109 | HIGH 8.1 | fortinet fortios An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary | 1.8% | — |
| CVE-2019-12207 | CRIT 9.8 | f5 njs njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. | 1.8% | — |
| CVE-2018-15396 | MED 6.8 | cisco unity_connection A vulnerability in the Bulk Administration Tool (BAT) for Cisco Unity Connection could allow an authenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected softw | 1.8% | — |