56.932 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.932 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-25667 | HIGH 7.5 | microsoft .net ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processin | 3.0% | — |
| CVE-2010-4563 | MED 5.0 | linux linux_kernel The Linux kernel, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping. | 3.0% | — |
| CVE-2001-0006 | HIGH 7.1 | microsoft windows_nt The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Wins | 3.0% | — |
| CVE-2020-1235 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1265, CVE-2020-1282, CVE | 3.0% | — |
| CVE-2018-1299 | HIGH 7.5 | apache allura In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers used with Allura, such as Nginx, Apache/mod_wsgi or paster may prevent the attack from succeeding. Others, such as gunicor | 3.0% | — |
| CVE-2012-6602 | HIGH 9.0 | paloaltonetworks pan-os The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 30122. | 3.0% | — |
| CVE-2012-6599 | HIGH 9.0 | paloaltonetworks pan-os The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 and 4.1.x before 4.1.1 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 33476. | 3.0% | — |
| CVE-2012-6598 | HIGH 9.0 | paloaltonetworks pan-os The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 33080. | 3.0% | — |
| CVE-2012-6595 | HIGH 9.0 | paloaltonetworks pan-os The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 34595. | 3.0% | — |
| CVE-2012-6594 | HIGH 9.0 | paloaltonetworks pan-os The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11, 4.0.x before 4.0.8, and 4.1.x before 4.1.1 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 34299. | 3.0% | — |
| CVE-2012-6591 | HIGH 9.0 | paloaltonetworks pan-os The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 31116. | 3.0% | — |
| CVE-2020-1950 | MED 5.5 | apache tika A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23. | 3.0% | — |
| CVE-2018-17622 | MED 6.5 | foxitsoftware phantompdf This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious f | 3.0% | — |
| CVE-2018-0345 | HIGH 8.8 | cisco vbond_orchestrator A vulnerability in the configuration and management database of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arbitrary commands with the privileges of the vmanage user in the configuration management system of the affected | 3.0% | — |
| CVE-2007-2688 | HIGH 7.8 | cisco ios The Cisco Intrusion Prevention System (IPS) and IOS with Firewall/IPS Feature Set do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic. | 3.0% | — |
| CVE-2022-36364 | HIGH 8.8 | apache apache_calcite_avatica Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` connection property; however, the driver does not verify if the class implements the expected interface before instantiating it, which can lead | 3.0% | — |
| CVE-2018-6972 | MED 6.5 | vmware esxi VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 before ESXi550-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain a denial-of-service vulnerability due | 3.0% | — |
| CVE-2015-0582 | MED 5.0 | cisco nx-os The High Availability (HA) subsystem in Cisco NX-OS on MDS 9000 devices allows remote attackers to cause a denial of service via crafted traffic, aka Bug ID CSCuo09129. | 3.0% | — |
| CVE-2012-4091 | MED 5.0 | cisco nx-os The RIP service engine in Cisco NX-OS allows remote attackers to cause a denial of service (engine restart) via a malformed (1) RIPv4 or (2) RIPv6 message, aka Bug ID CSCtj73415. | 3.0% | — |
| CVE-2021-43888 | HIGH 7.5 | microsoft defender_for_iot Microsoft Defender for IoT Information Disclosure Vulnerability | 3.0% | — |
| CVE-2021-43236 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability | 3.0% | — |
| CVE-2021-43222 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability | 3.0% | — |
| CVE-2016-1479 | HIGH 7.5 | cisco ip_phone_8800_series_firmware Cisco IP Phone 8800 devices with software 11.0(1) allow remote attackers to cause a denial of service (memory corruption) via a crafted HTTP request, aka Bug ID CSCuz03038. | 3.0% | — |
| CVE-2015-5572 | MED 5.0 | adobe air Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass intende | 3.0% | — |
| CVE-2010-0583 | HIGH 7.8 | cisco ios Memory leak in the H.323 implementation in Cisco IOS 12.1 through 12.4, and 15.0M before 15.0(1)M1, allows remote attackers to cause a denial of service (memory consumption and device reload) via malformed H.323 packets, aka Bug ID CSCtb93855. | 3.0% | — |