58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.046 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-9879 | HIGH 7.5 | ibm websphere_application_server An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "/" to a re | 1.4% | — |
| CVE-2016-9878 | HIGH 7.5 | pivotal_software spring_framework An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks. | 5.7% | — |
| CVE-2016-9680 | HIGH 7.5 | citrix provisioning_services Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors. | 1.9% | — |
| CVE-2016-9637 | HIGH 7.5 | citrix xenserver The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access. | 0.4% | — |
| CVE-2016-9418 | HIGH 7.5 | mybb merge_system MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows might allow remote attackers to obtain sensitive information from ACP backups via vectors involving a short name. | 2.3% | — |
| CVE-2016-9415 | HIGH 7.5 | mybb merge_system MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows allow remote attackers to overwrite arbitrary CSS files via vectors related to "style import." | 1.9% | — |
| CVE-2016-9381 | HIGH 7.5 | citrix xenserver Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability. | 0.3% | — |
| CVE-2016-9380 | HIGH 7.5 | citrix xenserver The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file. | 0.4% | — |
| CVE-2016-9312 | HIGH 7.5 | ntp ntp ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet. | 31.2% | — |
| CVE-2016-9256 | HIGH 7.5 | f5 big-ip_access_policy_manager In F5 BIG-IP 12.1.0 through 12.1.2, permissions enforced by iControl can lag behind the actual permissions assigned to a user if the role_map is not reloaded between the time the permissions are changed and the time of the user's next request. This is a race c | 1.0% | — |
| CVE-2016-9253 | HIGH 7.5 | f5 big-ip_access_policy_manager In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of service for virtual servers configured to use the websocket profile. | 1.3% | — |
| CVE-2016-9252 | HIGH 7.5 | f5 big-ip_access_policy_manager The Traffic Management Microkernel (TMM) in F5 BIG-IP before 11.5.4 HF3, 11.6.x before 11.6.1 HF2 and 12.x before 12.1.2 does not properly handle minimum path MTU options for IPv6, which allows remote attackers to cause a denial-of-service (DoS) through unspec | 1.8% | — |
| CVE-2016-9250 | HIGH 7.5 | f5 big-ip_access_policy_manager In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism. | 0.9% | — |
| CVE-2016-9249 | HIGH 7.5 | f5 big-ip_access_policy_manager An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Management Microkernel (TMM) to restart, resulting in a Denial-of-Service (DoS). | 2.0% | — |
| CVE-2016-9244 | HIGH 7.5 | f5 big-ip_access_policy_manager A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session | 74.0% | — |
| CVE-2016-9219 | HIGH 7.5 | cisco wireless_lan_controller_firmware A vulnerability with IPv6 UDP ingress packet processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an unexpected reload of the device. The vulnerability is due to incomplete IPv6 UDP header validati | 3.0% | — |
| CVE-2016-9212 | HIGH 7.5 | cisco web_security_appliance A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to connect to a secure website over Secure Sockets Layer (SSL) or Trans | 2.8% | — |
| CVE-2016-9211 | HIGH 7.5 | cisco ons_15454_sdh_multiservice_platform_software A vulnerability in TCP port management in Cisco ONS 15454 Series Multiservice Provisioning Platforms could allow an unauthenticated, remote attacker to cause the controller card to unexpectedly reload. More Information: CSCuw26032. Known Affected Releases: 10. | 3.5% | — |
| CVE-2016-9210 | HIGH 7.5 | cisco unified_communications_manager A vulnerability in the Cisco Unified Reporting upload tool accessed via the Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to modify arbitrary files on the file system. More Information: CSCvb61698. Known Affected Releases | 3.0% | — |
| CVE-2016-9205 | HIGH 7.5 | cisco ios_xr A vulnerability in the HTTP 2.0 request handling code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash, resulting in a denial of service (DoS) condition. More Information: CSC | 1.6% | — |
| CVE-2016-9203 | HIGH 7.5 | cisco asr_5000_series_software A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco ASR 5000 Series Software could allow an unauthenticated, remote attacker to cause a reload of the ipsecmgr process. More Information: CSCvb38398. Known Affected Releases: 20.2.3 20 | 3.5% | — |
| CVE-2016-9201 | HIGH 7.5 | cisco ios A vulnerability in the Zone-Based Firewall feature of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to pass traffic that should otherwise have been dropped based on the configuration. More Information: CSCuz21015. Known Af | 2.5% | — |
| CVE-2016-9198 | HIGH 7.5 | cisco identity_services_engine A vulnerability in the Active Directory integration component of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack. More Information: CSCuw15041. Known Affected Releases: 1.2(1.199) | 3.3% | — |
| CVE-2016-9193 | HIGH 7.5 | cisco firesight_system_software A vulnerability in the malicious file detection and blocking features of Cisco Firepower Management Center and Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass malware detection mechanisms on an affected system. Affecte | 2.0% | — |
| CVE-2016-9079 | HIGH 7.5 | debian debian_linux A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, a | 87.4% |