56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.959 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-3278 | HIGH 7.2 | cisco rv016_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu | 2.8% | — |
| CVE-2020-3277 | HIGH 7.2 | cisco rv016_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu | 2.8% | — |
| CVE-2020-3276 | HIGH 7.2 | cisco rv016_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu | 2.8% | — |
| CVE-2020-3275 | HIGH 7.2 | cisco rv016_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu | 2.8% | — |
| CVE-2020-3274 | HIGH 7.2 | cisco rv016_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu | 2.8% | — |
| CVE-2017-3029 | LOW 3.3 | adobe acrobat Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability when handling a JPEG 2000 code-stream. | 2.8% | — |
| CVE-2017-3020 | LOW 3.3 | adobe acrobat Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the weblink module. | 2.8% | — |
| CVE-2015-6112 | MED 5.8 | microsoft windows_7 SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 lacks the required extended master-secret binding support to ensure that a server's | 2.8% | — |
| CVE-2003-1430 | MED 5.0 | epic_games unreal_engine Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL. | 2.8% | — |
| CVE-2021-24100 | MED 5.0 | microsoft edge Microsoft Edge for Android Information Disclosure Vulnerability | 2.8% | — |
| CVE-2020-3177 | HIGH 7.5 | cisco unified_communications_manager A vulnerability in the Tool for Auto-Registered Phones Support (TAPS) of Cisco Unified Communications Manager (UCM) and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct directory t | 2.8% | — |
| CVE-2006-6589 | MED 6.8 | apache ofbiz Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue tha | 2.8% | — |
| CVE-2001-0163 | MED 4.6 | cisco aironet_ap340 Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections. | 2.8% | — |
| CVE-2022-34701 | HIGH 7.5 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability | 2.8% | — |
| CVE-2021-30611 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30611 Use after free in WebRTC | 2.8% | — |
| CVE-2014-3308 | MED 6.4 | cisco asr_9000_rsp440_router Cisco IOS XR on Trident line cards in ASR 9000 devices lacks a static punt policer, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted packets, aka Bug ID CSCun83985. | 2.8% | — |
| CVE-2025-46701 | HIGH 7.3 | apache tomcat Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0 | 2.8% | — |
| CVE-2014-3389 | HIGH 9.0 | cisco asa The VPN implementation in Cisco ASA Software 7.2 before 7.2(5.15), 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.15), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), 9.2 before 9.2(2.6), and 9.3 before 9.3(1.1) does not properl | 2.8% | — |
| CVE-2006-2074 | HIGH 10.0 | juniper junose Unspecified vulnerability in Juniper Networks JUNOSe E-series routers before 7-1-1 has unknown impact and remote attack vectors related to the DNS "client code," as demonstrated by the OUSPG PROTOS DNS test suite. | 2.8% | — |
| CVE-2011-0375 | HIGH 9.0 | cisco telepresence_system_1000 The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCth24671. | 2.8% | — |
| CVE-2011-0374 | HIGH 9.0 | cisco telepresence_system_1000 The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31659. | 2.8% | — |
| CVE-2011-0373 | HIGH 9.0 | cisco telepresence_system_1000 The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31685. | 2.8% | — |
| CVE-2022-26936 | MED 6.5 | microsoft windows_10 Windows Server Service Information Disclosure Vulnerability | 2.8% | — |
| CVE-2020-10964 | CRIT 9.8 | s9y serendipity Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename. | 2.8% | — |
| CVE-2025-47994 | HIGH 7.8 | microsoft 365_apps Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally. | 2.8% | — |