57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1273 | HIGH 8.6 | cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | 1.4% | — |
| CVE-2021-1241 | HIGH 8.6 | cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | 1.4% | — |
| CVE-2017-6624 | MED 5.3 | cisco ios A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remote attacker to make unauthorized phone calls. The vulnerability is due to a configuration restriction in the toll-fraud protections component | 1.4% | — |
| CVE-2017-5032 | HIGH 8.8 | google chrome PDFium in Google Chrome prior to 57.0.2987.98 for Windows could be made to increment off the end of a buffer, which allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | 1.4% | — |
| CVE-2013-5697 | HIGH 7.5 | simone_tellini mod_accounting SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header. | 1.4% | — |
| CVE-2022-34271 | HIGH 8.8 | apache atlas A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0. | 1.4% | — |
| CVE-2021-22012 | HIGH 7.5 | vmware cloud_foundation The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information. | 1.4% | — |
| CVE-2018-1000028 | HIGH 7.4 | linux linux_kernel Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading or writing files they should not be able to via NFS. This atta | 1.4% | — |
| CVE-2016-2066 | HIGH 7.8 | linux linux_kernel Integer signedness error in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (memory cor | 1.4% | — |
| CVE-2013-0891 | HIGH 7.5 | google chrome Integer overflow in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a blob. | 1.4% | — |
| CVE-2012-2474 | MED 4.0 | cisco 5500_series_adaptive_security_appliance Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 allows remote authenticated users to cause a denial of service (memory consumption and blank response page) by using the clientless WebVPN feature, aka Bu | 1.4% | — |
| CVE-2005-3177 | MED 4.6 | microsoft windows_2000 CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not | 1.4% | — |
| CVE-2023-38167 | HIGH 7.2 | microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2020-3517 | HIGH 8.6 | cisco firepower_extensible_operating_system A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated attacker to cause process crashes, which could result in a denial of service (DoS) condition on an affected device. The attack | 1.4% | — |
| CVE-2023-25695 | MED 5.3 | apache airflow Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2. | 1.4% | — |
| CVE-2022-46769 | MED 5.4 | apache sling_cms An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in the s | 1.4% | — |
| CVE-2021-1411 | CRIT 9.9 | cisco jabber Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, | 1.4% | — |
| CVE-2019-11272 | HIGH 7.3 | debian debian_linux Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a nul | 1.4% | — |
| CVE-2017-0074 | MED 5.4 | microsoft windows_10 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of se | 1.4% | — |
| CVE-2015-6362 | MED 4.0 | cisco connected_grid_network_management_system The web GUI in Cisco Connected Grid Network Management System (CG-NMS) 3.0(0.35) and 3.0(0.54) allows remote authenticated users to bypass intended access restrictions and modify the configuration by leveraging the Monitor-Only role, aka Bug ID CSCuw42640. | 1.4% | — |
| CVE-2011-0378 | HIGH 8.3 | cisco telepresence_system_1000 The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587. | 1.4% | — |
| CVE-2024-21416 | HIGH 8.1 | microsoft windows_10_1809 Windows TCP/IP Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-37536 | HIGH 8.2 | apache xerces-c\+\+ An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. | 1.4% | — |
| CVE-2023-21693 | MED 5.7 | microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-8567 | MED 4.9 | google secret_manager_provider_for_secret_store_csi_driver Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesyst | 1.4% | — |