57.725 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.725 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-4738 | MED 6.5 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated user from the dashboard UI which could be used in further attacks against the system. IBM X-Force ID: 172753. | 0.5% | — |
| CVE-2019-4732 | MED 6.5 | ibm sdk IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in | 0.6% | — |
| CVE-2019-4656 | MED 6.5 | ibm mq IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulnerable to a denial of service attack that would allow an authenticated user to crash the queue and require a restart due to an error processing error messages. IBM X-Force ID: 17096 | 1.4% | — |
| CVE-2019-4614 | MED 6.5 | ibm mq IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager could cause a SIGSEGV denial of service caused by converting an invalid message. IBM X-Force ID: 168639. | 1.6% | — |
| CVE-2019-4386 | MED 6.5 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a function that would cause the server to crash. IBM X-Force ID: 162714. | 2.1% | — |
| CVE-2019-3874 | MED 6.5 | canonical ubuntu_linux The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable. | 1.8% | — |
| CVE-2019-3799 | MED 6.5 | oracle communications_cloud_native_core_policy Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A mali | 85.3% | — |
| CVE-2019-3460 | MED 6.5 | canonical ubuntu_linux A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1. | 1.8% | — |
| CVE-2019-3459 | MED 6.5 | canonical ubuntu_linux A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1. | 1.8% | — |
| CVE-2019-1984 | MED 6.5 | cisco enterprise_network_function_virtualization_infrastructure_sofware A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite files on the underlying operating system (OS) of an affected device. T | 1.6% | — |
| CVE-2019-1953 | MED 6.5 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging the admin password when a user is forced t | 1.5% | — |
| CVE-2019-1946 | MED 6.5 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management interface. The vulnerabili | 1.4% | — |
| CVE-2019-19362 | MED 6.5 | teamviewer teamviewer An issue was discovered in the Chat functionality of the TeamViewer desktop application 14.3.4730 on Windows. (The vendor states that it was later fixed.) Upon login, every communication is saved within Windows main memory. When a user logs out or deletes conv | 2.1% | — |
| CVE-2019-19319 | MED 6.5 | linux linux_kernel In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a memset call, | 0.7% | — |
| CVE-2019-1915 | MED 6.5 | cisco unified_communications_manager A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Conne | 0.7% | — |
| CVE-2019-1906 | MED 6.5 | cisco prime_infrastructure A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual domain configuration, which could lead to privilege escalation. The vulnerability is due to improper validation | 1.3% | — |
| CVE-2019-19046 | MED 6.5 | fedoraproject fedora A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering ida_simple_get() failure, aka CID-4aa7afb0ee20. NOTE: | 2.7% | — |
| CVE-2019-1903 | MED 6.5 | cisco security_manager A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit | 2.2% | — |
| CVE-2019-1890 | MED 6.5 | cisco application_policy_infrastructure_controller A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, adjacent attacker to bypass security validations and connect | 0.6% | — |
| CVE-2019-1877 | MED 6.5 | cisco enterprise_chat_and_email A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through chat sessions. The vulnerability is due to insufficient authentication mechanisms on the file download functio | 1.4% | — |
| CVE-2019-1841 | MED 6.5 | cisco catalyst_center A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authentication. The vulnerability is due to insufficient validation of user-supplied in | 2.6% | — |
| CVE-2019-1820 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be res | 13.6% | — |
| CVE-2019-1819 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be res | 13.6% | — |
| CVE-2019-1818 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be res | 13.6% | — |
| CVE-2019-18177 | MED 6.5 | citrix application_delivery_controller_firmware In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update. | 0.6% | — |