57.436 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.436 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-34485 | MED 5.0 | microsoft .net .NET Core and Visual Studio Information Disclosure Vulnerability | 1.5% | — |
| CVE-2020-16901 | MED 5.0 | microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.</p> <p>To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploite | 1.5% | — |
| CVE-2019-1951 | MED 5.8 | cisco sd-wan_firmware A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters. The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker | 1.5% | — |
| CVE-2019-1724 | HIGH 8.8 | cisco rv320_dual_gigabit_wan_vpn_router_software A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. An at | 1.5% | — |
| CVE-2019-12697 | HIGH 7.5 | cisco firepower Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see th | 1.5% | — |
| CVE-2019-12696 | HIGH 7.5 | cisco firepower Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see th | 1.5% | — |
| CVE-2018-16884 | HIGH 8.0 | canonical ubuntu_linux A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can c | 1.5% | — |
| CVE-2015-6317 | MED 6.5 | cisco identity_services_engine_software Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926. | 1.5% | — |
| CVE-2013-1287 | HIGH 7.2 | microsoft windows_7 The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which all | 1.5% | — |
| CVE-2013-1286 | HIGH 7.2 | microsoft windows_7 The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which all | 1.5% | — |
| CVE-2013-1285 | HIGH 7.2 | microsoft windows_7 The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which all | 1.5% | — |
| CVE-2023-35303 | HIGH 8.8 | microsoft windows_10_1507 USB Audio Class System Driver Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2023-33008 | MED 5.3 | apache johnzon Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can craft up some JSON input that uses large numbers (numbers such as 1e20000000) that Apache Johnzon will deserialize into BigDecimal and mayb | 1.5% | — |
| CVE-2020-0736 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. | 1.5% | — |
| CVE-2020-0717 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0716. | 1.5% | — |
| CVE-2020-0716 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0717. | 1.5% | — |
| CVE-2020-0705 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Network Dri | 1.5% | — |
| CVE-2020-0698 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Telephony Service improperly discloses the contents of its memory, aka 'Windows Information Disclosure Vulnerability'. | 1.5% | — |
| CVE-2020-0658 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. | 1.5% | — |
| CVE-2017-3817 | MED 4.3 | cisco unified_computing_system_director A vulnerability in the role-based resource checking functionality of Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in a UCS domain. More Information: CSCvc32 | 1.5% | — |
| CVE-2016-9644 | HIGH 7.8 | linux linux_kernel The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel 4.4.22 through 4.4.28 contains extended asm statements that are incompatible with the exception table, which allows local users to obtain root access on non-SMEP platforms via a | 1.5% | — |
| CVE-2015-2323 | MED 6.4 | fortinet fortios FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets. | 1.5% | — |
| CVE-2023-36796 | HIGH 7.8 | microsoft .net Visual Studio Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2023-36794 | HIGH 7.8 | microsoft .net Visual Studio Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2023-36793 | HIGH 7.8 | microsoft .net Visual Studio Remote Code Execution Vulnerability | 1.5% | — |