56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.855 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2008-3806 | HIGH 8.5 | cisco ios Cisco IOS 12.0 through 12.4 on Cisco 10000, uBR10012 and uBR7200 series devices handles external UDP packets that are sent to 127.0.0.0/8 addresses intended for IPC communication within the device, which allows remote attackers to cause a denial of service (de | 3.1% | — |
| CVE-2004-1436 | HIGH 7.5 | cisco optical_networking_systems_software The Transaction Language 1 (TL1) login interface in Cisco ONS 15327 4.6(0) and 4.6(1) and 15454 and 15454 SDH 4.6(0) and 4.6(1), when a user account is configured with a blank password, allows remote attackers to gain unauthorized access by logging in with a p | 3.1% | — |
| CVE-2016-5393 | HIGH 8.8 | apache hadoop In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands with the same privileges as the HDFS service. | 3.1% | — |
| CVE-2006-3085 | HIGH 7.8 | linux linux_kernel xt_sctp in netfilter for Linux kernel before 2.6.17.1 allows attackers to cause a denial of service (infinite loop) via an SCTP chunk with a 0 length. | 3.1% | — |
| CVE-2020-1093 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who s | 3.1% | — |
| CVE-2020-1064 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacke | 3.1% | — |
| CVE-2020-1035 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who s | 3.1% | — |
| CVE-2018-4925 | HIGH 7.5 | adobe digital_editions Adobe Digital Editions versions 4.5.7 and below have an exploitable Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 3.1% | — |
| CVE-2021-28454 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2018-1316 | HIGH 7.5 | apache ode The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directory traversal, resulting in the potential writing of files under unwanted locations, the overwriting of existing files or | 3.1% | — |
| CVE-2008-3813 | HIGH 7.8 | cisco ios Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when the L2TP mgmt daemon process is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted L2TP packet. | 3.1% | — |
| CVE-2008-3799 | HIGH 7.8 | cisco ios Memory leak in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4, when VoIP is configured, allows remote attackers to cause a denial of service (memory consumption and voice-service outage) via unspecified valid SIP messages. | 3.1% | — |
| CVE-2024-26219 | HIGH 7.5 | microsoft windows_10_1809 HTTP.sys Denial of Service Vulnerability | 3.1% | — |
| CVE-1999-0382 | HIGH 7.2 | microsoft windows_nt The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges. | 3.1% | — |
| CVE-2024-26254 | HIGH 7.5 | microsoft windows_10_1809 Microsoft Virtual Machine Bus (VMBus) Denial of Service Vulnerability | 3.1% | — |
| CVE-2019-15961 | HIGH 7.5 | canonical ubuntu_linux A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficie | 3.1% | — |
| CVE-2014-3299 | MED 6.8 | cisco ios Cisco IOS allows remote authenticated users to cause a denial of service (device reload) via malformed IPsec packets, aka Bug ID CSCui79745. | 3.1% | — |
| CVE-2007-1884 | MED 6.8 | php php Multiple integer signedness errors in the printf function family in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 on 64 bit machines allow context-dependent attackers to execute arbitrary code via (1) certain negative argument numbers that arise in the php_formatt | 3.1% | — |
| CVE-2020-17528 | CRIT 9.1 | apache nuttx Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer offsets within TCP packets including beyond the length of the | 3.1% | — |
| CVE-2017-12249 | CRIT 9.1 | cisco meeting_server A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker to gain unauthenticated or unauthorized access to components of or sensitive information in an affected system | 3.1% | — |
| CVE-1999-0715 | MED 4.6 | microsoft windows_2000 Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry. | 3.1% | — |
| CVE-2015-2367 | LOW 2.1 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users | 3.1% | — |
| CVE-2010-4008 | MED 4.3 | apache openoffice libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a deni | 3.1% | — |
| CVE-2020-25672 | HIGH 7.5 | debian debian_linux A memory leak vulnerability was found in Linux kernel in llcp_sock_connect | 3.1% | — |
| CVE-2017-3858 | HIGH 8.8 | cisco ios_xe A vulnerability in the web framework of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation of HTTP parameters suppli | 3.1% | — |