56.775 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.775 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2009-0062 | HIGH 9.0 | cisco catalyst_3750_series_integrated_wireless_lan_controller Unspecified vulnerability in the Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.2.173.0 allows remote authenticated users to gain privileges v | 2.6% | — |
| CVE-2008-6474 | HIGH 9.0 | f5 tmos The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unspecified configuration settings related to Perl EP3 with templates, probably triggering static code injection. | 2.7% | — |
| CVE-2008-5416 | HIGH 9.0 | microsoft sql_server Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop Engine (MSDE 2000) SP4; SQL Server 2005 SP2 and 9.00.1399.06; SQL Server 2000 Desktop Engine (WMSDE) on Windows Server 2003 SP1 and SP2; and | 87.0% | — |
| CVE-2008-3538 | HIGH 9.0 | hp enterprise_discovery Unspecified vulnerability in HP Enterprise Discovery 2.0 through 2.52 on Windows allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the initial description of this CVE was inadvertently associated with libxml2, but it shoul | 3.6% | — |
| CVE-2008-2097 | HIGH 9.0 | vmware esx Buffer overflow in the openwsman management service in VMware ESXi 3.5 and ESX 3.5 allows remote authenticated users to gain privileges via an "invalid Content-Length." | 3.9% | — |
| CVE-2008-2053 | HIGH 9.0 | cisco unified_customer_voice_portal Unspecified vulnerability in Cisco Unified Customer Voice Portal (CVP) 4.0.x before 4.0(2)_ES14, 4.1.x before 4.1(1)_ES11, and 7.x before 7.0(1) allows remote authenticated users with administrator role privileges to create, modify, or delete a superuser accou | 3.0% | — |
| CVE-2008-1457 | HIGH 9.0 | microsoft windows-nt The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted even | 36.3% | — |
| CVE-2008-1456 | HIGH 9.0 | microsoft windows-nt Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription request that | 28.0% | — |
| CVE-2008-1446 | HIGH 9.0 | microsoft internet_information_services Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute | 46.3% | — |
| CVE-2008-1436 | HIGH 9.0 | microsoft windows-nt Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to | 36.8% | — |
| CVE-2008-0107 | HIGH 9.0 | microsoft data_engine Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 allows remote | 34.5% | — |
| CVE-2008-0106 | HIGH 9.0 | microsoft data_engine Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement. | 35.3% | — |
| CVE-2008-0086 | HIGH 9.0 | microsoft data_engine Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression. | 61.9% | — |
| CVE-2007-5539 | HIGH 9.0 | cisco unified_contact_center_enterprise Unspecified vulnerability in Cisco Unified Intelligent Contact Management Enterprise (ICME), Unified ICM Hosted (ICMH), Unified Contact Center Enterprise (UCCE), Unified Contact Center Hosted (UCCH), and System Unified Contact Center Enterprise (SUCCE) 7.1(5) | 2.1% | — |
| CVE-2007-4746 | HIGH 9.0 | cisco video_surveillance_ip_gateway_encoder_decoder The Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier have default passw | 2.1% | — |
| CVE-2007-4285 | HIGH 9.0 | cisco ios Unspecified vulnerability in Cisco IOS and Cisco IOS XR 12.x up to 12.3, including some versions before 12.3(15) and 12.3(14)T, allows remote attackers to obtain sensitive information (partial packet contents) or cause a denial of service (router or component | 2.8% | — |
| CVE-2007-3039 | HIGH 9.0 | microsoft message_queuing Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2 | 69.1% | — |
| CVE-2007-2034 | HIGH 9.0 | cisco wireless_control_system Unspecified vulnerability in Cisco Wireless Control System (WCS) before 4.0.87.0 allows remote authenticated users to gain the privileges of the SuperUsers group, and manage the application and its networks, related to the group membership of user accounts, ak | 2.1% | — |
| CVE-2007-0968 | HIGH 9.0 | cisco firewall_services_module Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in an ACL to be improperly evaluated, which allows remote authenticated users to bypass intended certain ACL prot | 2.0% | — |
| CVE-2007-0960 | HIGH 9.0 | cisco asa_5500 Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, allows remote authenticated users to gain privileges via unspecified vectors. | 2.6% | — |
| CVE-2006-4696 | HIGH 9.0 | microsoft windows_2000 Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability." | 43.5% | — |
| CVE-2006-1857 | HIGH 9.0 | linux linux_kernel Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed HB-ACK chunk. | 6.8% | — |
| CVE-1999-0886 | HIGH 9.0 | microsoft windows_nt The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager. | 21.6% | — |
| CVE-2026-58154 | HIGH 8.9 | apache traffic_server Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrad | 0.4% | — |
| CVE-2023-27524 | HIGH 8.9 | apache superset Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resourc | 97.4% |