57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-20951 | HIGH 7.7 | cisco broadworks_messaging_server A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to insuffic | 2.0% | — |
| CVE-2022-20927 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. Thi | 0.5% | — |
| CVE-2022-20924 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) cond | 0.8% | — |
| CVE-2022-20920 | HIGH 7.7 | cisco ios A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional sit | 0.9% | — |
| CVE-2022-20808 | HIGH 7.7 | cisco smart_software_manager_on-prem A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect handling of multiple simultaneous dev | 1.0% | — |
| CVE-2022-20692 | HIGH 7.7 | cisco ios_xe A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. This vulnerability is due to insufficient resource managem | 1.1% | — |
| CVE-2022-20664 | HIGH 7.7 | cisco email_security_appliance A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to retrieve sensitive information | 1.0% | — |
| CVE-2021-47356 | HIGH 7.7 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mISDN: fix possible use-after-free in HFC_cleanup() This module's remove path calls del_timer(). However, that function does not wait until the timer handler finishes. This means that the ti | 0.3% | — |
| CVE-2021-47044 | HIGH 7.7 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix shift-out-of-bounds in load_balance() Syzbot reported a handful of occurrences where an sd->nr_balance_failed can grow to much higher values than one would expect. A success | 0.3% | — |
| CVE-2021-40463 | HIGH 7.7 | microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.6% | — |
| CVE-2021-34699 | HIGH 7.7 | cisco ios A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to an improper interaction between the web UI and the CLI parser. A | 1.2% | — |
| CVE-2021-33758 | HIGH 7.7 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 2.8% | — |
| CVE-2021-32586 | HIGH 7.7 | fortinet fortimail An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically crafted HTTP requests. | 1.1% | — |
| CVE-2021-26859 | HIGH 7.7 | microsoft power_bi_report_server Microsoft Power BI Information Disclosure Vulnerability | 3.0% | — |
| CVE-2021-26429 | HIGH 7.7 | microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-26416 | HIGH 7.7 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 3.9% | — |
| CVE-2021-23017 | HIGH 7.7 | f5 nginx A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. | 53.5% | — |
| CVE-2021-1692 | HIGH 7.7 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 3.9% | — |
| CVE-2021-1691 | HIGH 7.7 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 3.8% | — |
| CVE-2021-1638 | HIGH 7.7 | microsoft windows_10 Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software | 1.2% | — |
| CVE-2021-1623 | HIGH 7.7 | cisco ios_xe A vulnerability in the Simple Network Management Protocol (SNMP) punt handling function of Cisco cBR-8 Converged Broadband Routers could allow an authenticated, remote attacker to overload a device punt path, resulting in a denial of service (DoS) condition. T | 1.1% | — |
| CVE-2021-1620 | HIGH 7.7 | cisco ios A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to exhaust the free IP addresses from the assigned local pool. Th | 1.1% | — |
| CVE-2021-1422 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker or an unauthenticated attacker in a man-in-the-middle positi | 1.2% | — |
| CVE-2020-8022 | HIGH 7.7 | apache tomcat A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-S | 0.9% | — |
| CVE-2020-3982 | HIGH 7.7 | vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI de | 0.8% | — |