56.696 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.696 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-36909 | CRIT 9.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail | 0.2% | — |
| CVE-2024-35939 | CRIT 9.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dma-direct: Leak pages on dma_set_decrypted() failure On TDX it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is ret | 0.2% | — |
| CVE-2024-28752 | CRIT 9.3 | apache cxf A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the d | 2.5% | — |
| CVE-2024-22267 | CRIT 9.3 | vmware fusion VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on th | 0.7% | — |
| CVE-2024-22253 | CRIT 9.3 | vmware cloud_foundation VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runn | 0.6% | — |
| CVE-2024-22252 | CRIT 9.3 | vmware esxi VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runn | 3.5% | — |
| CVE-2024-21364 | CRIT 9.3 | microsoft azure_site_recovery Microsoft Azure Site Recovery Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-20412 | CRIT 9.3 | cisco secure_firewall_threat_defense A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerability is due to the pre | 0.2% | — |
| CVE-2022-21817 | CRIT 9.3 | nvidia omniverse_launcher NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other security | 1.7% | — |
| CVE-2021-27080 | CRIT 9.3 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.3% | — |
| CVE-2020-7819 | CRIT 9.3 | ntracker ntracker_usb_enterprise A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. | 1.5% | — |
| CVE-2020-3955 | CRIT 9.3 | vmware esxi ESXi 6.5 without patch ESXi650-201912104-SG and ESXi 6.7 without patch ESXi670-202004103-SG do not properly neutralize script-related HTML when viewing virtual machines attributes. VMware has evaluated the severity of this issue to be in the Important severity | 1.3% | — |
| CVE-2020-36169 | CRIT 9.3 | veritas netbackup An issue was discovered in Veritas NetBackup through 8.3.0.1 and OpsCenter through 8.3.0.1. Processes using OpenSSL attempt to load and execute libraries from paths that do not exist by default on the Windows operating system. By default, on Windows systems, u | 0.4% | — |
| CVE-2020-36166 | CRIT 9.3 | veritas infoscale An issue was discovered in Veritas InfoScale 7.x through 7.4.2 on Windows, Storage Foundation through 6.1 on Windows, Storage Foundation HA through 6.1 on Windows, and InfoScale Operations Manager (aka VIOM) Windows Management Server 7.x through 7.4.2. On star | 0.4% | — |
| CVE-2020-36165 | CRIT 9.3 | veritas desktop_and_laptop_option An issue was discovered in Veritas Desktop and Laptop Option (DLO) before 9.4. On start-up, it loads the OpenSSL library from /ReleaseX64/ssl. This library attempts to load the /ReleaseX64/ssl/openssl.cnf configuration file, which does not exist. By default, o | 0.4% | — |
| CVE-2020-36164 | CRIT 9.3 | veritas enterprise_vault An issue was discovered in Veritas Enterprise Vault through 14.0. On start-up, it loads the OpenSSL library. The OpenSSL library then attempts to load the openssl.cnf configuration file (which does not exist) at the following locations in both the System drive | 0.4% | — |
| CVE-2020-36163 | CRIT 9.3 | veritas netbackup An issue was discovered in Veritas NetBackup and OpsCenter through 8.3.0.1. NetBackup processes using Strawberry Perl attempt to load and execute libraries from paths that do not exist by default on the Windows operating system. By default, on Windows systems, | 0.4% | — |
| CVE-2020-36162 | CRIT 9.3 | veritas cloudpoint An issue was discovered in Veritas CloudPoint before 8.3.0.1+hotfix. The CloudPoint Windows Agent leverages OpenSSL. This OpenSSL library attempts to load the \usr\local\ssl\openssl.cnf configuration file, which does not exist. By default, on Windows systems u | 0.4% | — |
| CVE-2020-36160 | CRIT 9.3 | veritas system_recovery An issue was discovered in Veritas System Recovery before 21.2. On start-up, it loads the OpenSSL library from \usr\local\ssl. This library attempts to load the from \usr\local\ssl\openssl.cnf configuration file, which does not exist. By default, on Windows sy | 0.4% | — |
| CVE-2019-1848 | CRIT 9.3 | cisco digital_network_architecture_center A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. The vulnerability is due to insufficient access restriction to ports necessary | 0.7% | — |
| CVE-2019-0007 | CRIT 9.3 | juniper junos The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible to a family of attacks which rely on the use of predictable IP ID sequence numbers as their base method of att | 1.7% | — |
| CVE-2018-3990 | CRIT 9.3 | wibu wibukey An exploitable pool corruption vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400). A specially crafted IRP request can cause a buffer overflow, resulting in kernel memory corruption and, pot | 0.6% | — |
| CVE-2016-0088 | CRIT 9.3 | microsoft windows_10 Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability." | 7.5% | — |
| CVE-2015-8456 | HIGH 9.3 | adobe air Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execu | 5.5% | — |
| CVE-2015-8450 | HIGH 9.3 | adobe air Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20. | 6.5% | — |