57.551 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-5073 | HIGH 8.8 | google chrome Use after free in print preview in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | 1.2% | — |
| CVE-2017-5056 | HIGH 8.8 | google chrome A use after free in Blink in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | 1.2% | — |
| CVE-2017-4928 | HIGH 7.5 | vmware vcenter_server The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these issues by sending a PO | 1.2% | — |
| CVE-2017-2310 | MED 5.3 | juniper junos_space A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions prior to 16.1R1 may permit certain crafted packets, representing a network integrity risk. | 1.2% | — |
| CVE-2016-5021 | MED 4.9 | f5 big-ip_access_policy_manager The iControl REST service in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before 12.0.0 HF3; BIG-IP GTM 11.5.x before 11.5.4 and 11.6.x before 11. | 1.2% | — |
| CVE-2013-3474 | MED 6.3 | cisco wireless_lan_controller The Web Administrator Interface on Cisco Wireless LAN Controller (WLC) devices allows remote authenticated users to cause a denial of service (device crash) by leveraging membership in the Full Manager managers group, Read Only managers group, or Lobby Ambassa | 1.2% | — |
| CVE-2023-32038 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2018-5542 | HIGH 8.1 | f5 big-ip_access_policy_manager F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.6, or 11.2.1-11.6.3.2 HTTPS health monitors do not validate the identity of the monitored server. | 1.2% | — |
| CVE-2022-2162 | HIGH 8.8 | fedoraproject fedora Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 103.0.5060.53 allowed a remote attacker to bypass file system access via a crafted HTML page. | 1.2% | — |
| CVE-2021-33768 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2020-8190 | HIGH 7.5 | citrix application_delivery_controller_firmware Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation. | 1.2% | — |
| CVE-2020-3238 | HIGH 8.1 | cisco iox A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an authenticated, remote attacker to write or modify arbitrary files in the virtual instance that is running on the affected device. The vulnerabi | 1.2% | — |
| CVE-2020-0904 | MED 6.5 | microsoft windows_10 <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.</p> <p>To exploit the vulnerability, an attacker who already has a privileged accoun | 1.2% | — |
| CVE-2020-0886 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the vulnerability, an attacker wo | 1.2% | — |
| CVE-2024-5914 | CRIT 9.8 | paloaltonetworks cortex_xsoar_commonscripts A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container. | 1.2% | — |
| CVE-2024-49050 | HIGH 8.8 | microsoft python Visual Studio Code Python Extension Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2024-21326 | CRIT 9.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2021-44879 | MED 5.5 | linux linux_kernel In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. | 1.2% | — |
| CVE-2021-43326 | HIGH 7.8 | automox automox Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory. | 1.2% | — |
| CVE-2017-6762 | MED 6.1 | cisco jabber_guest A vulnerability in the web-based management interface of Cisco Jabber Guest Server 10.6(9), 11.0(0), and 11.0(1) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface | 1.2% | — |
| CVE-2017-6761 | MED 6.1 | cisco finesse A vulnerability in the web-based management interface of Cisco Finesse 10.6(1) and 11.5(1) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device | 1.2% | — |
| CVE-2017-12212 | MED 6.1 | cisco unity_connection A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insuf | 1.2% | — |
| CVE-2016-8435 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis | 1.2% | — |
| CVE-2016-3134 | HIGH 8.4 | linux linux_kernel The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call. | 1.2% | — |
| CVE-2026-43512 | CRIT 9.8 | apache tomcat DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from | 1.2% | — |