58.444 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.444 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-15328 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not handled by the BIG-IP system Secure Vault | 2.3% | — |
| CVE-2018-15326 | HIGH 7.5 | f5 big-ip_access_policy_manager In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat revoked certificates as valid when the BIG-IP APM system fails to download a new Certificate Revocation List. | 0.6% | — |
| CVE-2018-15320 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, undisclosed traffic patterns may lead to denial of service conditions for the BIG-IP system. The configuration which exposes this condition is the BIG-IP self IP address which is part of a VLAN group and has the Po | 1.3% | — |
| CVE-2018-15319 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.6, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with the non-default "normalize URI" configuration options used in iRules and/or | 1.9% | — |
| CVE-2018-15318 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives an abort signal while the initial flow is not the primary flow, the initial flow will remain after the closing procedure is complete. TMM may restart and produc | 1.3% | — |
| CVE-2018-15317 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.2.1-11.6.3.2, an attacker sending specially crafted SSL records to a SSL Virtual Server will cause corruption in the SSL data structures leading to intermittent decrypt BAD_RECORD_MAC errors. | 1.4% | — |
| CVE-2018-14882 | HIGH 7.5 | apple mac_os_x The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c. | 3.9% | — |
| CVE-2018-14880 | HIGH 7.5 | apple mac_os_x The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr(). | 5.3% | — |
| CVE-2018-14735 | HIGH 7.5 | hitachi command_suite An Information Exposure issue was discovered in Hitachi Command Suite 8.5.3. A remote attacker may be able to exploit a flaw in the permission of messaging that may allow for information exposure via a crafted message. | 1.4% | — |
| CVE-2018-14608 | HIGH 7.5 | thomsonreuters ultratax_cs Thomson Reuters UltraTax CS 2017 on Windows has a password protection option; however, the level of protection might be inconsistent with some customers' expectations because the data is directly accessible in cleartext. Specifically, it stores customer data i | 0.9% | — |
| CVE-2018-14469 | HIGH 7.5 | apple mac_os_x The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print(). | 5.3% | — |
| CVE-2018-14468 | HIGH 7.5 | apple mac_os_x The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print(). | 4.0% | — |
| CVE-2018-14465 | HIGH 7.5 | apple mac_os_x The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print(). | 4.1% | — |
| CVE-2018-14463 | HIGH 7.5 | apple mac_os_x The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167. | 4.7% | — |
| CVE-2018-14462 | HIGH 7.5 | apple mac_os_x The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print(). | 4.0% | — |
| CVE-2018-13864 | HIGH 7.5 | lightbend play_framework A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when running on Windows. It allows a remote attacker to download arbitrary files from the target server via specially crafted | 3.4% | — |
| CVE-2018-1340 | HIGH 7.5 | apache guacamole Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's session token if unencrypted HTTP reque | 2.1% | — |
| CVE-2018-13376 | HIGH 7.5 | fortinet fortios An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causing sensitive data to be displayed in the HTTP response. | 2.1% | — |
| CVE-2018-1336 | HIGH 7.5 | apache tomcat An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to | 20.6% | — |
| CVE-2018-1333 | HIGH 7.5 | apache http_server By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33). | 17.1% | — |
| CVE-2018-1330 | HIGH 7.5 | apache mesos When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A ma | 3.7% | — |
| CVE-2018-1327 | HIGH 7.5 | apache struts The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrade to the Apache Struts version 2.5.16 and switch to an optional Jackson XML handl | 8.6% | — |
| CVE-2018-1323 | HIGH 7.5 | apache tomcat_jk_connector The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exp | 46.4% | — |
| CVE-2018-1320 | HIGH 7.5 | apache thrift Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be dis | 8.2% | — |
| CVE-2018-1318 | HIGH 7.5 | apache traffic_server Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or lat | 7.7% | — |