57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-1976 | MED 5.5 | mozilla firefox Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | 1.3% | — |
| CVE-2011-4022 | MED 5.0 | cisco intrusion_prevention_system The sensor in Cisco Intrusion Prevention System (IPS) 7.0 and 7.1 allows remote attackers to cause a denial of service (file-handle exhaustion and mainApp hang) by making authentication attempts that exceed the configured limit, aka Bug ID CSCto51204. | 1.3% | — |
| CVE-2022-24495 | HIGH 7.0 | microsoft windows_10 Windows Direct Show Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2021-31379 | HIGH 7.5 | juniper junos An Incorrect Behavior Order vulnerability in the MAP-E automatic tunneling mechanism of Juniper Networks Junos OS allows an attacker to send certain malformed IPv4 or IPv6 packets to cause a Denial of Service (DoS) to the PFE on the device which is disabled as | 1.3% | — |
| CVE-2017-5058 | HIGH 8.8 | google chrome A use after free in PrintPreview in Google Chrome prior to 58.0.3029.81 for Windows allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | 1.3% | — |
| CVE-2011-2839 | HIGH 7.5 | google chrome The PDF implementation in Google Chrome before 13.0.782.215 on Linux does not properly use the memset library function, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | 1.3% | — |
| CVE-2009-2056 | LOW 3.3 | cisco ios_xr Cisco IOS XR 3.8.1 and earlier allows remote authenticated users to cause a denial of service (process crash) via vectors involving a BGP UPDATE message with many AS numbers prepended to the AS path. | 1.3% | — |
| CVE-2009-1154 | LOW 3.3 | cisco ios_xr Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute. | 1.3% | — |
| CVE-2024-20679 | MED 6.5 | microsoft azure_stack_hub Azure Stack Hub Spoofing Vulnerability | 1.3% | — |
| CVE-2023-40610 | MED 6.3 | apache superset Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database connection that allows access to both the examples schema and Apache Superset's metadata database, an attacker usin | 1.3% | — |
| CVE-2023-22665 | MED 5.4 | apache jena There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to execute arbitrary javascript via a SPARQL query. | 1.3% | — |
| CVE-2021-1464 | MED 5.0 | cisco catalyst_sd-wan_manager A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain restricted access to the configuration information of an affected system. This vulnerability exists because the affec | 1.3% | — |
| CVE-2020-26076 | HIGH 7.5 | cisco iot_field_network_director A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive database information on an affected device. The vulnerability is due to the absence of authentication for sensitive information. An atta | 1.3% | — |
| CVE-2019-0632 | HIGH 7.8 | microsoft powershell_core A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0631. | 1.3% | — |
| CVE-2019-0631 | HIGH 7.8 | microsoft powershell_core A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0632. | 1.3% | — |
| CVE-2016-9253 | HIGH 7.5 | f5 big-ip_access_policy_manager In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of service for virtual servers configured to use the websocket profile. | 1.3% | — |
| CVE-2021-36959 | MED 5.5 | microsoft windows_10 Windows Authenticode Spoofing Vulnerability | 1.3% | — |
| CVE-2021-1491 | MED 6.5 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying file system of the device. This vulnerability is due to insufficient file scope | 1.3% | — |
| CVE-2020-2001 | HIGH 8.1 | paloaltonetworks pan-os An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that allows an unauthenticated user with network access to PAN-OS management interface to write attacker supplied file on the system and elevate | 1.3% | — |
| CVE-2018-8142 | MED 5.3 | microsoft windows_10 A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1035. | 1.3% | — |
| CVE-2018-15320 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, undisclosed traffic patterns may lead to denial of service conditions for the BIG-IP system. The configuration which exposes this condition is the BIG-IP self IP address which is part of a VLAN group and has the Po | 1.3% | — |
| CVE-2024-43581 | HIGH 7.1 | microsoft windows_10_1809 Microsoft OpenSSH for Windows Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2020-19695 | CRIT 9.8 | f5 njs Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function. | 1.3% | — |
| CVE-2020-17135 | MED 6.4 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1.3% | — |
| CVE-2018-5501 | MED 5.9 | f5 big-ip_access_policy_manager In some circumstances, on F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, any 11.6.x or 11.5.x release, or 11.2.1, TCP DNS profile allows excessive buffering due to lack of flow control. | 1.3% | — |