57.411 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.411 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22213 | MED 5.9 | juniper junos A vulnerability in Handling of Undefined Values in the routing protocol daemon (RPD) process of Juniper Networks Junos OS and Junos OS Evolved may allow an unauthenticated network-based attacker to crash the RPD process by sending a specific BGP update while t | 0.7% | — |
| CVE-2022-22208 | MED 5.9 | juniper junos A Use After Free vulnerability in the Routing Protocol Daemon (rdp) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause Denial of Service (DoS). When a BGP session flap happens, a Use After Free of a memo | 0.5% | — |
| CVE-2022-22169 | MED 5.9 | juniper junos An Improper Initialization vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker who sends specific packets in certain orders and at specific timings to force OSPFv3 to unexpectedly enter gracef | 0.8% | — |
| CVE-2022-22028 | MED 5.9 | microsoft windows_server_2008 Windows Network File System Information Disclosure Vulnerability | 2.4% | — |
| CVE-2022-21221 | MED 5.9 | fasthttp_project fasthttp The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslash %5c character in the path. **Note:** This security issue i | 2.5% | — |
| CVE-2022-1678 | MED 5.9 | linux linux_kernel An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients. | 2.9% | — |
| CVE-2022-0023 | MED 5.9 | paloaltonetworks pan-os An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to send specifically crafted traffic to the firewall that causes the service to resta | 0.7% | — |
| CVE-2021-45105 | MED 5.9 | apache log4j Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a craft | 100.0% | — |
| CVE-2021-40122 | MED 5.9 | cisco meeting_server A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper handling of large series of message requests. An at | 1.2% | — |
| CVE-2021-39090 | MED 5.9 | ibm cloud_pak_for_security IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive | 0.4% | — |
| CVE-2021-39072 | MED 5.9 | ibm security_guardium IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the mid | 1.3% | — |
| CVE-2021-38978 | MED 5.9 | ibm security_guardium_key_lifecycle_manager IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive i | 0.9% | — |
| CVE-2021-38933 | MED 5.9 | ibm sterling_connect\ IBM Sterling Connect:Direct for UNIX 1.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210574. | 0.4% | — |
| CVE-2021-38542 | MED 5.9 | apache james Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information. | 2.3% | — |
| CVE-2021-38153 | MED 5.9 | apache kafka Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or highe | 6.3% | — |
| CVE-2021-3714 | MED 5.9 | linux linux_kernel A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the | 1.5% | — |
| CVE-2021-33764 | MED 5.9 | microsoft windows_server_2008 Windows Key Distribution Center Information Disclosure Vulnerability | 3.5% | — |
| CVE-2021-32791 | MED 5.9 | fedoraproject fedora mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, the AES GCM encrypti | 1.5% | — |
| CVE-2021-31957 | MED 5.9 | fedoraproject fedora ASP.NET Core Denial of Service Vulnerability | 5.1% | — |
| CVE-2021-31364 | MED 5.9 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability combined with a Race Condition in the flow daemon (flowd) of Juniper Networks Junos OS on SRX300 Series, SRX500 Series, SRX1500, and SRX5000 Series with SPC2 allows an unauthenticated networ | 0.7% | — |
| CVE-2021-3048 | MED 5.9 | paloaltonetworks pan-os Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding. This condition causes subsequent commits on the firewall to fail and prevents administrators from performing commits and config | 0.8% | — |
| CVE-2021-29785 | MED 5.9 | ibm soar IBM Security SOAR V42 and V43could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the m | 1.3% | — |
| CVE-2021-29779 | MED 5.9 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in the middle techniques. IBM X-Force ID: 203033. | 1.2% | — |
| CVE-2021-29692 | MED 5.9 | ibm security_identity_manager IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man i | 1.0% | — |
| CVE-2021-27195 | MED 5.9 | netop vision_pro Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic. | 0.8% | — |