57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-16026 | MED 5.9 | cisco staros A vulnerability in the implementation of the Stream Control Transmission Protocol (SCTP) on Cisco Mobility Management Entity (MME) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an eNodeB that is connected to an | 1.4% | — |
| CVE-2017-7755 | HIGH 7.8 | mozilla firefox The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows ope | 1.4% | — |
| CVE-2016-1383 | HIGH 7.5 | cisco web_security_appliance_\(wsa\) Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an unspecified HTTP status code, aka Bug ID CSCur28305. | 1.4% | — |
| CVE-2016-1381 | HIGH 7.5 | cisco web_security_appliance Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an HTTP file-range request for cached content, aka Bug ID CSCuw97270. | 1.4% | — |
| CVE-2016-1263 | HIGH 7.5 | juniper junos Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3X48 before 12.3X48-D30, 13.3 before 13.3R9-S1, 14.1 before 14.1R7, 14.2 before 14.2R6, 15.1 before 15.1F2-S5, 15.1F4 before 15.1F4-S2, 15.1R before 15.1R2-S3, 15.1 before 15.1R3, | 1.4% | — |
| CVE-2000-0654 | MED 4.6 | microsoft sql_server Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability. | 1.4% | — |
| CVE-2024-38167 | MED 6.5 | microsoft .net .NET and Visual Studio Information Disclosure Vulnerability | 1.4% | — |
| CVE-2024-23320 | HIGH 8.8 | apache dolphinscheduler Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we | 1.4% | — |
| CVE-2022-45347 | CRIT 9.8 | apache shardingsphere Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client. This | 1.4% | — |
| CVE-2021-39064 | HIGH 7.5 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Admin console. IBM X-Force ID: 214957. | 1.4% | — |
| CVE-2020-3808 | MED 5.9 | adobe creative_cloud Creative Cloud Desktop Application versions 5.0 and earlier have a time-of-check to time-of-use (toctou) race condition vulnerability. Successful exploitation could lead to arbitrary file deletion. | 1.4% | — |
| CVE-2020-17045 | MED 5.5 | microsoft windows_10 Windows KernelStream Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-17036 | MED 5.5 | microsoft windows_10 Windows Function Discovery SSDP Provider Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-17030 | MED 5.5 | microsoft windows_10 Windows MSCTF Server Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-17029 | MED 5.5 | microsoft windows_10 Windows Canonical Display Driver Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-1640 | HIGH 7.5 | juniper junos An improper use of a validation framework when processing incoming genuine BGP packets within Juniper Networks RPD (routing protocols process) daemon allows an attacker to crash RPD thereby causing a Denial of Service (DoS) condition. This framework requires t | 1.4% | — |
| CVE-2020-0874 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'. T | 1.4% | — |
| CVE-2011-3297 | HIGH 7.8 | cisco catalyst_6500 Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authentication configurations are used, allows remote attackers to cause a denial of service (module crash) by making many | 1.4% | — |
| CVE-2009-4923 | HIGH 7.8 | cisco asa_5580 Unspecified vulnerability in the DTLS implementation on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (traceback) via TLS fragments, aka Bug ID CSCso53162. | 1.4% | — |
| CVE-2009-4920 | HIGH 7.8 | cisco asa_5580 Unspecified vulnerability in CTM on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software 8.1(2) allows remote attackers to cause a denial of service (watchdog traceback) via a large amount of small-packet data, aka Bug ID CSCsu11412. | 1.4% | — |
| CVE-2009-4918 | HIGH 7.8 | cisco asa_5580 Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remote attackers to cause a denial of service (IKE process hang) via malformed NAT-T packets, aka Bug ID CSCsr74439. | 1.4% | — |
| CVE-2009-4917 | HIGH 7.8 | cisco asa_5580 Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device reload) via a high volume of SIP traffic, aka Bug ID CSCsr65901. | 1.4% | — |
| CVE-2002-1557 | MED 5.0 | cisco optical_networking_systems_software Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset to TCC, TCC+, TCCi or XTC) via a malformed HTTP request that does not contain a leading / (slash) character. | 1.4% | — |
| CVE-2002-1556 | MED 5.0 | cisco optical_networking_systems_software Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset) via an HTTP request to the TCC, TCC+ or XTC, in which the request contains an invalid CORBA Interoperable Object Reference (IOR). | 1.4% | — |
| CVE-2021-22116 | HIGH 7.5 | debian debian_linux RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending malicious AMQP messages to the target Rabbit | 1.4% | — |