57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.620 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-3405 | MED 4.3 | cisco telepresence_tc_software The web portal in TC software on Cisco TelePresence endpoints does not require an exact password match during a login attempt by a user who has not configured a password, which allows remote attackers to bypass authentication by sending an arbitrary password, | 1.2% | — |
| CVE-2002-1706 | HIGH 7.5 | cisco ios Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal Broadband Routers allows remote attackers to modify Data Over Cable Service Interface Specification (DOCSIS) settings via a DOCSIS file without a Message Integrity Check | 1.2% | — |
| CVE-2024-29831 | HIGH 8.8 | apache dolphinscheduler Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2. | 1.2% | — |
| CVE-2023-38429 | CRIT 9.8 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access. | 1.2% | — |
| CVE-2022-20694 | MED 6.8 | cisco ios_xe A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Border Gateway Protocol (BGP) process to crash, resulting in a denial of servic | 1.2% | — |
| CVE-2021-36089 | HIGH 7.8 | zope grok Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::applyColour). | 1.2% | — |
| CVE-2026-58627 | HIGH 7.5 | microsoft windows_10_1607 Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-54983 | HIGH 7.5 | microsoft windows_10_1607 Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-54119 | HIGH 7.5 | microsoft windows_10_1607 Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50696 | HIGH 7.5 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50695 | HIGH 7.5 | microsoft windows_10_1607 Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50653 | HIGH 7.5 | microsoft .net_framework Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50647 | HIGH 7.5 | microsoft .net_framework Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50506 | HIGH 7.5 | microsoft asp.net_core_odata Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50496 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. | 1.2% | — |
| CVE-2026-50424 | HIGH 7.5 | microsoft windows_11_24h2 Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50411 | HIGH 7.5 | microsoft .net_framework Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50368 | HIGH 7.5 | microsoft .net_framework Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50355 | HIGH 7.5 | microsoft .net_framework Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50304 | HIGH 7.5 | microsoft windows_10_1607 Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-49788 | HIGH 7.5 | microsoft windows_10_1607 Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-49787 | HIGH 7.5 | microsoft windows_10_1607 Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-45646 | HIGH 7.5 | microsoft asp.net_core_odata Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-44806 | MED 5.3 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-40378 | HIGH 7.5 | microsoft windows_10_1607 Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | 1.2% | — |