56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.832 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-1999-0162 | MED 5.0 | cisco ios The "established" keyword in some Cisco IOS software allowed an attacker to bypass filtering. | 1.7% | — |
| CVE-1999-0158 | MED 5.0 | cisco pix_firewall_software Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known. | 1.5% | — |
| CVE-1999-0157 | MED 5.0 | cisco ios Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service. | 1.1% | — |
| CVE-1999-0154 | MED 5.0 | microsoft internet_information_server IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL. | 40.0% | — |
| CVE-1999-0153 | MED 5.0 | microsoft windows_2000 Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke. | 21.1% | — |
| CVE-1999-0140 | MED 5.0 | microsoft windows_nt Denial of service in RAS/PPTP on NT systems. | 13.6% | — |
| CVE-1999-0128 | MED 5.0 | digital osf_1 Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. | 74.7% | — |
| CVE-1999-0107 | MED 5.0 | apache http_server Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters. | 19.9% | — |
| CVE-1999-0104 | MED 5.0 | caldera openlinux A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2. | 9.2% | — |
| CVE-1999-0077 | MED 5.0 | microsoft windows_nt Predictable TCP sequence numbers allow spoofing. | 30.9% | — |
| CVE-1999-0070 | MED 5.0 | apache http_server test-cgi program allows an attacker to list files on the server. | 29.6% | — |
| CVE-1999-0063 | MED 5.0 | cisco ios Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port. | 8.2% | — |
| CVE-1999-0016 | MED 5.0 | cisco ios Land IP denial of service. | 95.7% | — |
| CVE-1999-0015 | MED 5.0 | hp hp-ux Teardrop IP denial of service. | 35.7% | — |
| CVE-1999-0007 | MED 5.0 | c2net stonghold_web_server Information from SSL-encrypted sessions via PKCS #1. | 7.6% | — |
| CVE-2026-8672 | MED 5.1 | avantra avantra Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords. This issue affects Avantra: before 25.3.0. | 0.1% | — |
| CVE-2026-50418 | MED 5.1 | microsoft windows_11_24h2 Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-11276 | MED 5.1 | google chrome Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to bypass discretionary access control via malicious network traffic. (Chromium security severity: Low) | 0.1% | — |
| CVE-2025-55679 | MED 5.1 | microsoft windows_10_1809 Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2025-52989 | MED 5.1 | juniper junos An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. A user with limited configuration and commit p | 0.1% | — |
| CVE-2025-33069 | MED 5.1 | microsoft windows_11_24h2 Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2025-26644 | MED 5.1 | microsoft windows_10_1809 Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally. | 0.5% | — |
| CVE-2025-20117 | MED 5.1 | cisco application_policy_infrastructure_controller A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrativ | 0.2% | — |
| CVE-2024-47566 | MED 5.1 | fortinet fortirecorder A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI request | 0.2% | — |
| CVE-2024-45772 | MED 5.1 | apache lucene_replicator Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0. The deprecated org.apache.lucene.replicator.http package is affected. The org.apache.lucene.replicator | 0.6% | — |