56.560 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.560 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-51736 | NONE 0.0 | sensiolabs symfony Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing comman | 0.4% | — |
| CVE-2023-31007 | NONE 0.0 | apache pulsar Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authentication data expires if the client connected through the Pulsar Proxy when the broker is configured with authent | 1.0% | — |
| CVE-2023-20057 | NONE 0.0 | cisco asyncos A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improp | 0.7% | — |
| CVE-2013-4869 | LOW 0.0 | cisco unified_communications_manager Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) and the IM & Presence Service in Cisco Unified Presence Server through 9.1(2) use the same CTI and database-encryption key across different customers' installations, which makes it easier for co | 0.6% | — |
| CVE-1999-0612 | LOW 0.0 | gnu finger_service A version of finger is running that exposes valid user information to any entity on the network. | 67.4% | — |
| CVE-2012-2313 | LOW 1.2 | linux linux_kernel The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call. | 0.6% | — |
| CVE-2011-4415 | LOW 1.2 | apache http_server The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial | 3.1% | — |
| CVE-2010-3718 | LOW 1.2 | apache tomcat Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstra | 1.4% | — |
| CVE-2008-7256 | LOW 1.2 | linux linux_kernel mm/shmem.c in the Linux kernel before 2.6.28-rc8, when strict overcommit is enabled and CONFIG_SECURITY is disabled, does not properly handle the export of shmemfs objects by knfsd, which allows attackers to cause a denial of service (NULL pointer dereference | 0.3% | — |
| CVE-2007-2453 | LOW 1.2 | linux linux_kernel The random number feature in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, (1) does not properly seed pools when there is no entropy, or (2) uses an incorrect cast when extracting entropy, which might cause the random number generator to pro | 0.4% | — |
| CVE-2007-0833 | LOW 1.2 | vmware workstation VMware Workstation 5.5.3 34685, when the "Enable copy and paste to and from this virtual machine" option is enabled, preserves clipboard data on the guest operating system after it was deleted on the host operating system, which might allow local users to read | 0.3% | — |
| CVE-2007-0832 | LOW 1.2 | vmware workstation VMware Workstation 5.5.3 34685 does not immediately change the availability of a shared clipboard when the "Enable copy and paste to and from this virtual machine" checkbox is changed, which allows local users to obtain sensitive information or conduct certain | 0.3% | — |
| CVE-2006-5757 | LOW 1.2 | linux linux_kernel Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versions allows local users to cause a denial of service (infinite loop) by mounting a crafted ISO9660 filesystem containing malformed data struct | 0.8% | — |
| CVE-2006-1066 | LOW 1.2 | linux linux_kernel Linux kernel 2.6.16-rc2 and earlier, when running on x86_64 systems with preemption enabled, allows local users to cause a denial of service (oops) via multiple ptrace tasks that perform single steps, which can cause corruption of the DEBUG_STACK stack during | 0.3% | — |
| CVE-2006-0741 | LOW 1.2 | linux linux_kernel Linux kernel before 2.6.15.5, when running on Intel processors, allows local users to cause a denial of service ("endless recursive fault") via unknown attack vectors related to a "bad elf entry address." | 0.4% | — |
| CVE-2005-1368 | LOW 1.2 | linux linux_kernel The key_user_lookup function in security/keys/key.c in Linux kernel 2.6.10 to 2.6.11.8 may allow attackers to cause a denial of service (oops) via SMP. | 0.4% | — |
| CVE-2005-0937 | LOW 1.2 | linux linux_kernel Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executing mma | 0.3% | — |
| CVE-2004-1069 | LOW 1.2 | linux linux_kernel Race condition in SELinux 2.6.x through 2.6.9 allows local users to cause a denial of service (kernel crash) via SOCK_SEQPACKET unix domain sockets, which are not properly handled in the sock_dgram_sendmsg function. | 0.3% | — |
| CVE-2004-1058 | LOW 1.2 | linux linux_kernel Race condition in Linux kernel 2.6 allows local users to read the environment variables of another process that is still spawning via /proc/.../cmdline. | 0.4% | — |
| CVE-2004-0814 | LOW 1.2 | linux linux_kernel Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attackers t | 0.7% | — |
| CVE-2003-0462 | LOW 1.2 | linux linux_kernel A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash). | 0.6% | — |
| CVE-1999-1042 | LOW 1.2 | cisco resource_manager Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings. | 0.3% | — |
| CVE-2012-5616 | LOW 1.5 | apache cloudstack Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, ( | 0.6% | — |
| CVE-2011-1637 | LOW 1.5 | cisco skinny_client_control_protocol_software Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows local users to gain privileges via a crafted image, aka Bug ID CSCtn65962. | 0.3% | — |
| CVE-2014-1444 | LOW 1.7 | linux linux_kernel The fst_get_iface function in drivers/net/wan/farsync.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capabil | 0.3% | — |