IT
58.007 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.007 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2018-8012 HIGH 7.5 apache zookeeper No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to th 8.5%
CVE-2018-8011 HIGH 7.5 apache http_server By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33). 56.0%
CVE-2018-7719 HIGH 7.5 acrolinx acrolinx_server Acrolinx Server before 5.2.5 on Windows allows Directory Traversal. 46.9%
CVE-2018-7449 HIGH 7.5 segger embos\/ip_ftp_server SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an invalid LIST, STOR, or RETR command. 7.5%
CVE-2018-7340 HIGH 7.5 cisco duo_network_gateway Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attac 0.9%
CVE-2018-6810 HIGH 7.5 citrix netscaler_application_delivery_controller_firmware Directory traversal vulnerability in NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allows remote attackers to traverse the directory on the target system via a crafted request. 4.4%
CVE-2018-6808 HIGH 7.5 citrix netscaler_application_delivery_controller_firmware NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the target system. 2.3%
CVE-2018-6757 HIGH 7.5 mcafee true_key Privilege Escalation vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafted malware. 1.1%
CVE-2018-6412 HIGH 7.5 linux linux_kernel In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands. 2.3%
CVE-2018-6237 HIGH 7.5 trendmicro smart_protection_server A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the product to send a large number of specially crafted HTTP requests to potentially cause the file system to fill up, eventual 6.4%
CVE-2018-5743 HIGH 7.5 f5 big-ip_access_policy_manager By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which w 6.5%
CVE-2018-5549 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP APM 11.6.0-11.6.3.1, 12.1.0-12.1.3.3, 13.0.0, and 13.1.0-13.1.0.3, APMD may core when processing SAML Assertion or response containing certain elements. 1.8%
CVE-2018-5544 HIGH 7.5 f5 big-ip_access_policy_manager When the F5 BIG-IP APM 13.0.0-13.1.1 or 12.1.0-12.1.3 renders certain pages (pages with a logon agent or a confirm box), the BIG-IP APM may disclose configuration information such as partition and agent names via URI parameters. 2.5%
CVE-2018-5541 HIGH 7.5 f5 big-ip_application_security_manager When F5 BIG-IP ASM 13.0.0-13.1.0.1, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.5.1-11.5.6 is processing HTTP requests, an unusually large number of parameters can cause excessive CPU usage in the BIG-IP ASM bd process. 1.8%
CVE-2018-5539 HIGH 7.5 f5 big-ip_application_security_manager Under certain conditions, on F5 BIG-IP ASM 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, 11.5.1-11.5.6, or 11.2.1, when processing CSRF protections, the BIG-IP ASM bd process may restart and produce a core file. 1.8%
CVE-2018-5536 HIGH 7.5 f5 big-ip_access_policy_manager A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 virtual server configured with an APM per-request policy object and cause a memory leak in the APM module. 2.4%
CVE-2018-5535 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP 14.0.0, 13.0.0-13.1.0, 12.1.0-12.1.3, or 11.5.1-11.6.3 specifically crafted HTTP responses, when processed by a Virtual Server with an associated QoE profile that has Video enabled, may cause TMM to incorrectly buffer response data causing the TMM 2.6%
CVE-2018-5534 HIGH 7.5 f5 big-ip_access_policy_manager Under certain conditions on F5 BIG-IP 13.1.0-13.1.0.5, 13.0.0, 12.1.0-12.1.3.1, 11.6.0-11.6.3.1, or 11.5.0-11.5.6, TMM may core while processing SSL forward proxy traffic. 1.8%
CVE-2018-5533 HIGH 7.5 f5 big-ip_access_policy_manager Under certain conditions on F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.0-11.6.3.1, or 11.5.0-11.5.6, TMM may core while processing SSL forward proxy traffic. 1.8%
CVE-2018-5530 HIGH 7.5 f5 big-ip_access_policy_manager F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.1 virtual servers with HTTP/2 profiles enabled are vulnerable to "HPACK Bomb". 1.8%
CVE-2018-5527 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 13.1.0-13.1.0.7, a remote attacker using undisclosed methods against virtual servers configured with a Client SSL or Server SSL profile that has the SSL Forward Proxy feature enabled can force the Traffic Management Microkernel (tmm) to leak memory. 2.5%
CVE-2018-5517 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP 13.1.0-13.1.0.5, malformed TCP packets sent to a self IP address or a FastL4 virtual server may cause an interruption of service. The control plane is not exposed to this issue. This issue impacts the data plane virtual servers and self IPs. 1.7%
CVE-2018-5514 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when the HTTP2 profile is enabled. There is no control plane exposure to this issue. 3.9%
CVE-2018-5513 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handshake causes TMM to crash leading to a disruption of service. This issue is only exposed on the data plane when Proxy SSL configuration is ena 1.8%
CVE-2018-5512 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP 13.1.0-13.1.0.5, when Large Receive Offload (LRO) and SYN cookies are enabled (default settings), undisclosed traffic patterns may cause TMM to restart. 3.0%