IT
57.139 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.139 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2017-6153 MED 5.3 f5 big-ip_access_policy_manager Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes inflate functionality directly, via an iRule, or via the inflate code from PEM module are subjected to a service disruption via a "Zip Bomb" 1.7%
CVE-2017-3826 HIGH 7.5 cisco netflow_generation_appliance_software A vulnerability in the Stream Control Transmission Protocol (SCTP) decoder of the Cisco NetFlow Generation Appliance (NGA) with software before 1.1(1a) could allow an unauthenticated, remote attacker to cause the device to hang or unexpectedly reload, causing 1.7%
CVE-2015-4322 MED 5.5 cisco content_security_management_appliance Cisco Content Security Management Appliance (SMA) 8.3.6-039, 9.1.0-31, and 9.1.0-103 improperly restricts the privileges available after LDAP authentication, which allows remote authenticated users to read or write to an arbitrary user's Spam Quarantine folder 1.7%
CVE-2004-1198 MED 5.0 Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays. 1.7%
CVE-2002-0643 MED 4.6 microsoft data_engine The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted 1.7%
CVE-2022-30196 HIGH 8.2 microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability 1.7%
CVE-2019-1844 MED 5.3 cisco email_security_appliance A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected device. The vulnerability is due to improper detection o 1.7%
CVE-2017-17544 HIGH 7.2 fortinet fortios A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile to super_admin via restoring modified configurations. 1.7%
CVE-2014-0225 HIGH 8.8 pivotal_software spring_framework When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack. 1.7%
CVE-2022-35759 MED 6.5 microsoft windows_10_1507 Windows Local Security Authority (LSA) Denial of Service Vulnerability 1.7%
CVE-2020-4870 HIGH 7.5 ibm mq IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications. IBM X-Force ID: 190833. 1.7%
CVE-2020-15250 MED 4.4 apache pluto In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like systems, the system's temporary directory is shared between all users on that system. Because of this, when files an 1.7%
CVE-2020-0926 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- 1.7%
CVE-2010-1969 MED 4.3 hp virtual_connect_enterprise_manager Cross-site scripting (XSS) vulnerability in HP Virtual Connect Enterprise Manager for Windows before 6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. 1.7%
CVE-2022-20656 MED 6.5 cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. To exploit this vulnerability, the attacker must have valid crede 1.7%
CVE-2021-40708 HIGH 7.3 adobe genuine_service Adobe Genuine Service versions 7.3 (and earlier) are affected by a privilege escalation vulnerability in the AGSService installer. An authenticated attacker could leverage this vulnerability to achieve read / write privileges to execute arbitrary code. User in 1.7%
CVE-2015-5359 HIGH 7.1 juniper junos Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D10, 13.2 before 13.2R7, 13.3 before 13.3R5, 14.1R3 before 14.1R3-S2, 14.1 before 14.1R4, 14.2 before 14.2R2, and 15 1.7%
CVE-2012-0519 HIGH 7.1 oracle database_server Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.2.0.2, when running on Windows, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. 1.7%
CVE-2010-0312 MED 5.0 ibm tivoli_directory_server The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted SecureWay 3.2 Event Registration Request (aka a 1.3.18.0.2.1 1.7%
CVE-2024-43534 MED 6.5 microsoft windows_10_1507 Windows Graphics Component Information Disclosure Vulnerability 1.7%
CVE-2023-36913 MED 6.5 microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability 1.7%
CVE-2023-36736 MED 4.4 microsoft identity_linux_broker Microsoft Identity Linux Broker Remote Code Execution Vulnerability 1.7%
CVE-2019-6605 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, and 12.0.x, an undisclosed sequence of packets received by an SSL virtual server and processed by an associated Client SSL or Server SSL profile may cause a denial of service. 1.7%
CVE-2017-6770 MED 4.2 cisco adaptive_security_appliance_software Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS 4.0 through 12.0, and IOS XE 3.6 through 3.18 are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Adverti 1.7%
CVE-2015-6355 MED 5.0 cisco unified_computing_system The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version information by visiting an unspecified URL, aka Bug ID CSCuw87226. 1.7%