57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-30048 | HIGH 7.6 | microsoft dynamics_365_customer_insights Dynamics 365 Customer Insights Spoofing Vulnerability | 1.0% | — |
| CVE-2024-30047 | HIGH 7.6 | microsoft dynamics_365_customer_insights Dynamics 365 Customer Insights Spoofing Vulnerability | 1.0% | — |
| CVE-2022-22319 | MED 5.4 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could cause disruption for any scripts dependent on the queue. IBM X-Force ID: 218366. | 1.0% | — |
| CVE-2020-36401 | HIGH 7.8 | mruby mruby mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free). | 1.0% | — |
| CVE-2020-3197 | MED 5.3 | cisco meeting_server A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials that are configured in an affected system. The vulnerability is due to insuff | 1.0% | — |
| CVE-2015-4458 | MED 4.3 | cisco adaptive_security_appliance_software The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9.1(5.21) and other products, does not verify the MAC field, which allows man-in-the-middle attackers to spoof TLS content | 1.0% | — |
| CVE-2005-2709 | MED 4.6 | linux linux_kernel The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (kernel oops) and possibly execute code by opening an interface file in /proc/sys/net/ipv4/conf/, waiting until the interface is unregistered, t | 1.0% | — |
| CVE-2025-49681 | MED 6.5 | microsoft windows_server_2008 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2025-49671 | MED 6.5 | microsoft windows_server_2008 Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2021-29728 | MED 4.9 | ibm sterling_external_authentication_server IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal da | 1.0% | — |
| CVE-2020-16853 | HIGH 7.1 | microsoft onedrive <p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status.</p> <p>To | 1.0% | — |
| CVE-2019-12415 | MED 5.5 | apache poi In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External En | 1.0% | — |
| CVE-2017-0304 | MED 5.4 | f5 big-ip_advanced_firewall_manager A SQL injection vulnerability exists in the BIG-IP AFM management UI on versions 12.0.0, 12.1.0, 12.1.1, 12.1.2 and 13.0.0 that may allow a copy of the firewall rules to be tampered with and impact the Configuration Utility until there is a resync of the rules | 1.0% | — |
| CVE-2013-0884 | MED 6.8 | google chrome Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly load Native Client (aka NaCl) code, which has unspecified impact and attack vectors. | 1.0% | — |
| CVE-2025-60006 | MED 5.3 | juniper junos_os_evolved Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges and/or execute unauthorized commands. When | 1.0% | — |
| CVE-2024-49103 | MED 4.3 | microsoft windows_10_1809 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | 1.0% | — |
| CVE-2024-49099 | MED 4.3 | microsoft windows_10_1809 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | 1.0% | — |
| CVE-2024-49098 | MED 4.3 | microsoft windows_10_1809 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | 1.0% | — |
| CVE-2022-27507 | MED 6.5 | citrix application_delivery_controller Authenticated denial of service | 1.0% | — |
| CVE-2022-22473 | MED 5.3 | ibm websphere_application_server IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data. This information could be used in further attacks against the system. IBM X-Force | 1.0% | — |
| CVE-2019-1590 | HIGH 8.1 | cisco nx-os A vulnerability in the Transport Layer Security (TLS) certificate validation functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to perform insecure TLS client a | 1.0% | — |
| CVE-2019-11599 | HIGH 7.0 | linux linux_kernel The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sensitive information, cause a denial of service, or possibly ha | 1.0% | — |
| CVE-2018-0119 | MED 4.7 | cisco conference_director A vulnerability in certain authentication controls in the account services of Cisco Spark could allow an authenticated, remote attacker to interact with and view information on an affected device that would normally be prohibited. The vulnerability is due to t | 1.0% | — |
| CVE-2015-0736 | MED 6.8 | cisco mediasense Cross-site request forgery (CSRF) vulnerability in Cisco MediaSense 10.5(1) and earlier allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu16728. | 1.0% | — |
| CVE-2015-0704 | MED 6.8 | cisco unified_meetingplace Multiple cross-site request forgery (CSRF) vulnerabilities in API features in Cisco Unified MeetingPlace 8.6(1.9) allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus95884. | 1.0% | — |