IT
57.551 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.551 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2023-32056 HIGH 7.8 microsoft windows_10_1809 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability 1.2%
CVE-2021-3772 MED 6.5 debian debian_linux A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses. 1.2%
CVE-2021-26418 MED 4.6 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 1.2%
CVE-2020-5891 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, undisclosed HTTP/2 requests can lead to a denial of service when sent to a virtual server configured with the Fallback Host setting and a server-side HTTP/2 profile. 1.2%
CVE-2020-1749 HIGH 7.5 linux linux_kernel A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the kernel isn't correctly routing tunneled data over the encrypted 1.2%
CVE-2020-1679 HIGH 7.5 juniper junos On Juniper Networks PTX and QFX Series devices with packet sampling configured using tunnel-observation mpls-over-udp, sampling of a malformed packet can cause the Kernel Routing Table (KRT) queue to become stuck. KRT is the module within the Routing Process D 1.2%
CVE-2019-1933 MED 5.8 cisco email_security_appliance A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device. The vulnerability is due to improper input validation o 1.2%
CVE-2018-10648 CRIT 9.8 citrix xenmobile_server There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. 1.2%
CVE-2024-51569 HIGH 7.5 apache nimble Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invalid read from HCI transport memory. This issue requires broken or bogus Bluetooth 1.2%
CVE-2024-49048 HIGH 8.1 microsoft torchgeo TorchGeo Remote Code Execution Vulnerability 1.2%
CVE-2024-29178 HIGH 8.8 apache streampark On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability. Mitigat 1.2%
CVE-2024-24683 MED 6.5 apache hop_engine Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to version 2.8.0, which fixes the issue. When Hop Server writes links to the PrepareExecutionPipelineServlet pag 1.2%
CVE-2023-51770 HIGH 7.5 apache dolphinscheduler Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue. 1.2%
CVE-2022-45438 MED 5.3 apache superset When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior 1.2%
CVE-2018-0135 MED 4.3 cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software improperly validates user-supplied search input. 1.2%
CVE-2017-12365 MED 4.3 cisco webex_meeting_center A vulnerability in Cisco WebEx Event Center could allow an authenticated, remote attacker to view unlisted meeting information. The vulnerability is due to a design flaw in the product. An attacker could execute a query on an Event Center site to view schedule 1.2%
CVE-2017-0295 MED 5.5 microsoft windows_10 Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Windows Default Folder Tampering Vulnerability". 1.2%
CVE-2007-4372 HIGH 10.0 netwin surgemail Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendor 1.2%
CVE-2025-21253 MED 5.3 microsoft edge Microsoft Edge for IOS and Android Spoofing Vulnerability 1.2%
CVE-2023-36722 MED 4.4 microsoft windows_10_1507 Active Directory Domain Services Information Disclosure Vulnerability 1.2%
CVE-2004-0424 HIGH 7.2 linux linux_kernel Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option. 1.2%
CVE-2024-45498 HIGH 8.8 apache airflow Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an authenticated attacker with only DAG trigger permission to execute arbitrary commands. If you used that example as the base of your DAGs - p 1.2%
CVE-2022-20816 MED 6.5 cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to delete arbitrary fi 1.2%
CVE-2020-16982 MED 6.1 microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability 1.2%
CVE-2019-0775 MED 4.7 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0702, CVE-2019-0755, CVE-2019-0767, CVE-2019-0782. 1.2%