57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2002-0049 | MED 6.4 | microsoft exchange_server Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys. | 13.3% | — |
| CVE-2001-1210 | MED 6.4 | cisco ubr920 Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remote attackers to read and write information to the MIB using arbitrary community s | 2.3% | — |
| CVE-2001-0723 | MED 6.4 | microsoft internet_explorer Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability." | 11.4% | — |
| CVE-2001-0722 | MED 6.4 | microsoft internet_explorer Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability." | 27.6% | — |
| CVE-2000-0979 | MED 6.4 | microsoft windows_95 File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the r | 45.0% | — |
| CVE-2000-0770 | MED 6.4 | microsoft internet_information_server IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" | 15.1% | — |
| CVE-2000-0760 | MED 6.4 | apache tomcat The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension. | 62.5% | — |
| CVE-2000-0759 | MED 6.4 | apache tomcat Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path. | 25.7% | — |
| CVE-2000-0024 | MED 6.4 | microsoft internet_information_server IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability. | 12.2% | — |
| CVE-1999-1361 | MED 6.4 | microsoft windows_nt Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages. | 8.6% | — |
| CVE-1999-1097 | MED 6.4 | microsoft netmeeting Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty. | 3.8% | — |
| CVE-1999-0191 | MED 6.4 | microsoft internet_information_server IIS newdsn.exe CGI script allows remote users to overwrite files. | 53.3% | — |
| CVE-1999-0183 | MED 6.4 | linux linux_kernel Linux implementations of TFTP would allow access to files outside the restricted directory. | 1.6% | — |
| CVE-1999-0074 | MED 6.4 | freebsd freebsd Listening TCP ports are sequentially allocated, allowing spoofing attacks. | 8.4% | — |
| CVE-2026-9981 | MED 6.5 | google chrome Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-9953 | MED 6.5 | google chrome Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-9882 | MED 6.5 | google chrome Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Critical) | 0.2% | — |
| CVE-2026-9639 | MED 6.5 | canonical lxd Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that o | 0.5% | — |
| CVE-2026-9262 | MED 6.5 | canon eos_network_setting_tool Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier | 0.3% | — |
| CVE-2026-9259 | MED 6.5 | canon eos_network_setting_tool Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier | 0.2% | — |
| CVE-2026-9258 | MED 6.5 | canon eos_network_setting_tool Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier | 0.3% | — |
| CVE-2026-9186 | MED 6.5 | langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.). | 0.3% | — |
| CVE-2026-9153 | MED 6.5 | gnu sed Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient input validation. | 0.5% | — |
| CVE-2026-9138 | MED 6.5 | langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local file paths using attacker‑controlled input | 0.3% | — |
| CVE-2026-87454 | MED 6.5 | google chrome Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | 0.2% | — |