57.479 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-16970 | HIGH 8.1 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.4% | — |
| CVE-2016-7223 | MED 6.1 | microsoft windows_10 Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted a | 1.4% | — |
| CVE-2012-2495 | MED 4.3 | cisco anyconnect_secure_mobility_client The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 and Cisco Secure Desktop before 3.6.6020 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attacke | 1.4% | — |
| CVE-2012-2494 | MED 4.3 | cisco anyconnect_secure_mobility_client The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 and 3.x before 3.0 MR8 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attac | 1.4% | — |
| CVE-2011-0396 | HIGH 7.8 | cisco adaptive_security_appliance Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.23), 8.1 before 8.1(2.49), 8.2 before 8.2(4.1), and 8.3 before 8.3(2.13), when a Certificate Authority (CA) is configured, allow remote attackers to read arbitrary file | 1.4% | — |
| CVE-2025-49716 | HIGH 7.5 | microsoft windows_server_2008 Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network. | 1.4% | — |
| CVE-2023-46714 | HIGH 7.2 | fortinet fortios A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs | 1.4% | — |
| CVE-2023-32336 | HIGH 8.8 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285. | 1.4% | — |
| CVE-2020-3321 | LOW 3.3 | cisco webex_network_recording_player A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnera | 1.4% | — |
| CVE-2019-1409 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Remote Procedure Call (RPC) runtime improperly initializes objects in memory, aka 'Windows Remote Procedure Call Information Disclosure Vulnerability'. | 1.4% | — |
| CVE-2016-6446 | HIGH 7.5 | cisco meeting_server A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0. | 1.4% | — |
| CVE-2016-6410 | MED 6.5 | cisco ios The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuy19856. | 1.4% | — |
| CVE-2012-2859 | HIGH 7.5 | google chrome Google Chrome before 21.0.1180.57 on Linux does not properly handle tabs, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors. | 1.4% | — |
| CVE-2024-36512 | HIGH 7.2 | fortinet fortianalyzer An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 allows attacker to execute unauthorized cod | 1.4% | — |
| CVE-2023-36043 | MED 6.5 | microsoft system_center_operations_manager Open Management Infrastructure Information Disclosure Vulnerability | 1.4% | — |
| CVE-2023-29354 | MED 4.7 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 1.4% | — |
| CVE-2020-1686 | HIGH 7.5 | juniper junos On Juniper Networks Junos OS devices, receipt of a malformed IPv6 packet may cause the system to crash and restart (vmcore). This issue can be trigged by a malformed IPv6 packet destined to the Routing Engine. An attacker can repeatedly send the offending pack | 1.4% | — |
| CVE-2019-15258 | MED 6.5 | cisco spa112_firmware A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper valid | 1.4% | — |
| CVE-2018-8116 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists in the way that Windows handles objects in memory, aka "Microsoft Graphics Component Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server | 1.4% | — |
| CVE-2016-2076 | HIGH 7.6 | vmware vcenter_server Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack session | 1.4% | — |
| CVE-2016-1345 | HIGH 7.5 | cisco asa_with_firepower_services Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka Bug ID CSCux22726. | 1.4% | — |
| CVE-2023-36882 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2021-1594 | HIGH 7.5 | cisco identity_services_engine A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a command injection attack and elevate privileges to root. This vulnerability is due to insufficient input validation for specifi | 1.4% | — |
| CVE-2020-4365 | MED 4.3 | ibm websphere_application_server IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964. | 1.4% | — |
| CVE-2011-1233 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted applica | 1.4% | — |