57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-1556 | MED 6.4 | hp systems_insight_manager Unspecified vulnerability in HP Systems Insight Manager (SIM) 5.3, 5.3 Update 1, and 6.0 allows remote attackers to obtain sensitive information and modify data via unknown vectors. | 2.2% | — |
| CVE-2003-0112 | MED 4.6 | microsoft windows_2000 Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger. | 2.2% | — |
| CVE-2020-9745 | MED 6.1 | adobe media_encoder Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locati | 2.2% | — |
| CVE-2012-5785 | MED 5.8 | apache axis2 Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrar | 2.2% | — |
| CVE-2024-26581 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect an end interval element that has been just added in this transactions, skip end interval e | 2.2% | — |
| CVE-2023-30846 | CRIT 9.1 | microsoft typed-rest-client typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties. The flow of the vulnerability is as fol | 2.2% | — |
| CVE-2021-34534 | MED 6.8 | microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2017-3165 | MED 5.4 | apache brooklyn In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site scripting where one authenticated user can cause scripts to run in the browser of another user authorized to access the first user's resources. This is due to improper escaping of se | 2.2% | — |
| CVE-2015-4203 | MED 5.4 | cisco ios Race condition in Cisco IOS 12.2SCH in the Performance Routing Engine (PRE) module on uBR10000 devices, when NetFlow and an MPLS IPv6 VPN are configured, allows remote attackers to cause a denial of service (PXF process crash) by sending malformed MPLS 6VPE pa | 2.2% | — |
| CVE-2007-1913 | MED 5.0 | sap rfc_library The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users and groups on systems and domains via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: T | 2.2% | — |
| CVE-2006-4194 | MED 5.0 | cisco pix_firewall_501 Unspecified vulnerability in Cisco PIX 500 Series Security Appliances allows remote attackers to send arbitrary UDP packets to intranet devices via unspecified vectors involving Session Initiation Protocol (SIP) fixup commands, a different issue than CVE-2006- | 2.2% | — |
| CVE-2022-38045 | HIGH 8.8 | microsoft windows_10 Windows Server Service Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2020-24490 | MED 6.5 | bluez bluez Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access. This affects all Linux kernel versions that support BlueZ. | 2.2% | — |
| CVE-2019-1742 | MED 5.3 | cisco ios_xe A vulnerability in the web UI of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access sensitive configuration information. The vulnerability is due to improper access control to files within the web UI. An attacker could exploit this | 2.2% | — |
| CVE-2015-2472 | MED 4.3 | microsoft windows_10 Remote Desktop Session Host (RDSH) in Remote Desktop Protocol (RDP) through 8.1 in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not pro | 2.2% | — |
| CVE-2021-39829 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requ | 2.2% | — |
| CVE-2020-3411 | HIGH 7.5 | cisco catalyst_center A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. The vulnerability is due to improper handling of authentication tokens by the affected software. An attacker coul | 2.2% | — |
| CVE-2018-15448 | HIGH 7.5 | cisco registered_envelope_service A vulnerability in the user management functions of Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to discover sensitive user information. The attacker could use this information to conduct additional reconnaissance attacks. | 2.2% | — |
| CVE-2022-35838 | HIGH 7.5 | microsoft windows_11 HTTP V3 Denial of Service Vulnerability | 2.2% | — |
| CVE-2021-25642 | HIGH 8.8 | apache hadoop ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users shou | 2.2% | — |
| CVE-2021-24117 | MED 4.9 | apache teaclave_sgx_sdk In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in is | 2.2% | — |
| CVE-2013-7470 | MED 5.9 | linux linux_kernel cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310 | 2.2% | — |
| CVE-2018-8651 | MED 5.4 | microsoft dynamics_nav A cross site scripting vulnerability exists when Microsoft Dynamics NAV does not properly sanitize a specially crafted web request to an affected Dynamics NAV server, aka "Microsoft Dynamics NAV Cross Site Scripting Vulnerability." This affects Microsoft Dynam | 2.2% | — |
| CVE-2009-4420 | HIGH 7.8 | f5 big-ip_application_security_manager Buffer overflow in the bd daemon in F5 Networks BIG-IP Application Security Manager (ASM) 9.4.4 through 9.4.7 and 10.0.0 through 10.0.1, and Protocol Security Manager (PSM) 9.4.5 through 9.4.7 and 10.0.0 through 10.0.1, allows remote attackers to cause a denia | 2.2% | — |
| CVE-2008-0751 | MED 4.3 | s9y serendipity_event_freetag Cross-site scripting (XSS) vulnerability in the Freetag before 2.96 plugin for S9Y Serendipity, when using Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to plugin/tag/. | 2.2% | — |