IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-33141 HIGH 7.5 microsoft yet_another_reverse_proxy Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability 2.2%
CVE-2023-32030 HIGH 7.5 microsoft .net_framework .NET and Visual Studio Denial of Service Vulnerability 2.2%
CVE-2024-43565 HIGH 7.5 microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability 2.2%
CVE-2024-43562 HIGH 7.5 microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability 2.2%
CVE-2024-43545 HIGH 7.5 microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability 2.2%
CVE-2024-43544 HIGH 7.5 microsoft windows_server_2008 Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability 2.2%
CVE-2022-33677 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability 2.2%
CVE-2022-33633 HIGH 7.2 microsoft lync_server Skype for Business and Lync Remote Code Execution Vulnerability 2.2%
CVE-2021-26422 HIGH 7.2 microsoft lync_server Skype for Business and Lync Remote Code Execution Vulnerability 2.2%
CVE-2021-1719 HIGH 8.0 microsoft sharepoint_enterprise_server Microsoft SharePoint Elevation of Privilege Vulnerability 2.2%
CVE-2007-5460 MED 4.6 microsoft windows_mobile Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when sending the user's PIN/Password over the USB connection from the host to the device, which might make it easier for attackers to decode a PIN/ 2.2%
CVE-2018-0007 CRIT 9.8 juniper junos An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to the local segment, through a local segment broadcast, may be able to cause a Junos device to enter an improper boundary check condition allowing a memory corruption to 2.2%
CVE-2005-0176 MED 5.0 linux linux_kernel The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released. 2.2%
CVE-2024-26202 HIGH 7.2 microsoft windows_server_2012 DHCP Server Service Remote Code Execution Vulnerability 2.2%
CVE-2024-26195 HIGH 7.2 microsoft windows_server_2008 DHCP Server Service Remote Code Execution Vulnerability 2.2%
CVE-2020-1523 HIGH 8.9 microsoft sharepoint_server <p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data.</p> <p>To exploit the vulnerability, an attacker 2.2%
CVE-2002-0507 LOW 2.1 microsoft exchange_server An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, 2.2%
CVE-2020-10867 CRIT 9.8 avast antivirus An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access restrictions on tasks from an untrusted process, when Self Defense is enabled. 2.2%
CVE-2019-6617 MED 6.5 f5 big-ip_access_policy_manager On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, a user with the Resource Administrator role is able to overwrite sensitive low-level files (such as /etc/passwd) using SFTP to modify user permissions, without Advan 2.2%
CVE-2016-1566 MED 5.4 apache guacamole Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location shared by multiple users, allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename. N 2.2%
CVE-2019-0754 MED 5.5 microsoft windows_10 A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. 2.2%
CVE-2017-3153 MED 6.1 apache atlas Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality. 2.2%
CVE-2017-3152 MED 6.1 apache atlas Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality. 2.2%
CVE-2018-5536 HIGH 7.5 f5 big-ip_access_policy_manager A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 virtual server configured with an APM per-request policy object and cause a memory leak in the APM module. 2.2%
CVE-2017-8486 MED 4.7 microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure due to the way it handles objects in memory, ak 2.2%