IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2007-1258 MED 6.1 cisco catalyst_6000 Unspecified vulnerability in Cisco IOS 12.2SXA, SXB, SXD, and SXF; and the MSFC2, MSFC2a and MSFC3 running in Hybrid Mode on Cisco Catalyst 6000, 6500 and Cisco 7600 series systems; allows remote attackers on a local network segment to cause a denial of servic 1.0%
CVE-2026-23906 CRIT 9.8 apache druid Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension enabled * LDAP authenticator configured * Underlying LDAP server permits an 1.0%
CVE-2024-26181 MED 5.5 microsoft windows_10_1507 Windows Kernel Denial of Service Vulnerability 1.0%
CVE-2023-51656 CRIT 9.8 apache iotdb Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended to upgrade to version 1.2.2, which fixes the issue. 1.0%
CVE-2023-30429 CRIT 9.6 apache pulsar Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. When a client connects to the Pulsar Function Worker via the Pulsar Proxy where the Pulsar Proxy uses mTLS authent 1.0%
CVE-2021-24018 MED 4.3 fortinet fortios A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may allow an attacker located in the adjacent network to potentially execute arbitrary code via a specifically crafted firmware image. 1.0%
CVE-2020-1011 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows System Assessment Tool improperly handles file operations, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-0983, CVE-2020-1009, CVE-2020-1015 1.0%
CVE-2020-1009 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Microsoft Store Install Service handles file operations in protected locations, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-0983, CVE- 1.0%
CVE-2019-6608 MED 5.9 f5 big-ip_access_policy_manager On BIG-IP 11.5.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, the snmpd daemon may leak memory on a multi-blade BIG-IP vCMP guest when processing authorized SNMP requests. 1.0%
CVE-2011-4487 MED 6.8 cisco business_edition_3000 SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with s 1.0%
CVE-2026-66713 CRIT 9.8 apache axis2\/java Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthentic 1.0%
CVE-2026-48567 CRIT 10.0 microsoft azure_horizondb Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. 1.0%
CVE-2024-49088 HIGH 7.8 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 1.0%
CVE-2024-26248 HIGH 7.5 microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability 1.0%
CVE-2023-36730 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 1.0%
CVE-2023-35348 MED 6.5 microsoft windows_server_2016 Active Directory Federation Service Security Feature Bypass Vulnerability 1.0%
CVE-2021-34691 HIGH 7.5 idrive remotepc iDrive RemotePC before 4.0.1 on Linux allows denial of service. A remote and unauthenticated attacker can disconnect a valid user session by connecting to an ephemeral port. 1.0%
CVE-2017-10608 HIGH 7.5 juniper junos Any Juniper Networks SRX series device with one or more ALGs enabled may experience a flowd crash when traffic is processed by the Sun/MS-RPC ALGs. This vulnerability in the Sun/MS-RPC ALG services component of Junos OS allows an attacker to cause a repeated d 1.0%
CVE-2017-10607 HIGH 7.5 juniper junos Juniper Networks Junos OS 16.1R1, and services releases based off of 16.1R1, are vulnerable to the receipt of a crafted BGP Protocol Data Unit (PDU) sent directly to the router, which can cause the RPD routing process to crash and restart. Unlike BGP UPDATEs, 1.0%
CVE-2020-19725 HIGH 7.8 microsoft z3 There is a use-after-free vulnerability in file pdd_simplifier.cpp in Z3 before 4.8.8. It occurs when the solver attempt to simplify the constraints and causes unexpected memory access. It can cause segmentation faults or arbitrary code execution. 1.0%
CVE-2023-38741 HIGH 7.5 ibm txseries_for_multiplatform IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to 1.0%
CVE-2023-36881 MED 4.5 microsoft azure_hdinsight Azure Apache Ambari Spoofing Vulnerability 1.0%
CVE-2023-36877 MED 4.5 microsoft azure_hdinsight Azure Apache Oozie Spoofing Vulnerability 1.0%
CVE-2022-22183 HIGH 7.5 juniper junos_os_evolved An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect to a specific open IPv4 port, which in affected releases should otherwise be unreachable, to cause the CPU to c 1.0%
CVE-2021-40129 MED 4.9 cisco common_services_platform_collector A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to submit a SQL query through the CSPC configuration dashboard. This vulnerability is due to insufficient input vali 1.0%