IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2021-1273 HIGH 8.6 cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. 1.4%
CVE-2021-1241 HIGH 8.6 cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. 1.4%
CVE-2017-6624 MED 5.3 cisco ios A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remote attacker to make unauthorized phone calls. The vulnerability is due to a configuration restriction in the toll-fraud protections component 1.4%
CVE-2017-5032 HIGH 8.8 google chrome PDFium in Google Chrome prior to 57.0.2987.98 for Windows could be made to increment off the end of a buffer, which allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. 1.4%
CVE-2013-5697 HIGH 7.5 simone_tellini mod_accounting SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header. 1.4%
CVE-2022-34271 HIGH 8.8 apache atlas A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0. 1.4%
CVE-2021-22012 HIGH 7.5 vmware cloud_foundation The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information. 1.4%
CVE-2018-1000028 HIGH 7.4 linux linux_kernel Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading or writing files they should not be able to via NFS. This atta 1.4%
CVE-2016-2066 HIGH 7.8 linux linux_kernel Integer signedness error in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (memory cor 1.4%
CVE-2013-0891 HIGH 7.5 google chrome Integer overflow in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a blob. 1.4%
CVE-2012-2474 MED 4.0 cisco 5500_series_adaptive_security_appliance Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 allows remote authenticated users to cause a denial of service (memory consumption and blank response page) by using the clientless WebVPN feature, aka Bu 1.4%
CVE-2005-3177 MED 4.6 microsoft windows_2000 CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not 1.4%
CVE-2023-38167 HIGH 7.2 microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability 1.4%
CVE-2020-3517 HIGH 8.6 cisco firepower_extensible_operating_system A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated attacker to cause process crashes, which could result in a denial of service (DoS) condition on an affected device. The attack 1.4%
CVE-2023-25695 MED 5.3 apache airflow Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2. 1.4%
CVE-2022-46769 MED 5.4 apache sling_cms An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in the s 1.4%
CVE-2021-1411 CRIT 9.9 cisco jabber Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, 1.4%
CVE-2019-11272 HIGH 7.3 debian debian_linux Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a nul 1.4%
CVE-2017-0074 MED 5.4 microsoft windows_10 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of se 1.4%
CVE-2015-6362 MED 4.0 cisco connected_grid_network_management_system The web GUI in Cisco Connected Grid Network Management System (CG-NMS) 3.0(0.35) and 3.0(0.54) allows remote authenticated users to bypass intended access restrictions and modify the configuration by leveraging the Monitor-Only role, aka Bug ID CSCuw42640. 1.4%
CVE-2011-0378 HIGH 8.3 cisco telepresence_system_1000 The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587. 1.4%
CVE-2024-21416 HIGH 8.1 microsoft windows_10_1809 Windows TCP/IP Remote Code Execution Vulnerability 1.4%
CVE-2023-37536 HIGH 8.2 apache xerces-c\+\+ An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. 1.4%
CVE-2023-21693 MED 5.7 microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.4%
CVE-2020-8567 MED 4.9 google secret_manager_provider_for_secret_store_csi_driver Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesyst 1.4%