57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-3809 | MED 5.8 | cisco secure_firewall_management_center A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to prevent deployment of a complete and accurate rule base. More Information: CSCvb95281. Known Affected Releases: 6. | 2.2% | — |
| CVE-2025-27479 | HIGH 7.5 | microsoft windows_server_2012 Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network. | 2.2% | — |
| CVE-2025-27473 | HIGH 7.5 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. | 2.2% | — |
| CVE-2025-26641 | HIGH 7.5 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. | 2.2% | — |
| CVE-2021-1712 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2018-8649 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affects Windows 10, Windows Server 2019. | 2.2% | — |
| CVE-2014-3276 | MED 4.0 | cisco identity_services_engine_software Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial of service | 2.2% | — |
| CVE-2018-3182 | MED 6.5 | netapp oncommand_insight Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to co | 2.2% | — |
| CVE-2018-3137 | MED 6.5 | netapp oncommand_insight Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols | 2.2% | — |
| CVE-2016-6493 | CRIT 9.8 | citrix xenapp Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to memory permission. | 2.2% | — |
| CVE-2017-7671 | HIGH 7.5 | apache traffic_server There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump. | 2.2% | — |
| CVE-2022-47937 | CRIT 9.8 | apache sling_commons_json Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymo | 2.2% | — |
| CVE-2021-27266 | LOW 3.3 | foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 2.2% | — |
| CVE-2021-27264 | LOW 3.3 | foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 2.2% | — |
| CVE-2018-4210 | HIGH 8.8 | apple iphone_os In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks. | 2.2% | — |
| CVE-2014-6602 | MED 6.6 | microsoft nokia_asha_501 Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows physically proximate attackers to bypass the lock-screen protection mechanism, and read or modify contact information or dial arbitrary telephone numbers, by tapping the SOS Option an | 2.2% | — |
| CVE-2007-3794 | HIGH 10.0 | hitachi cosminexus_application_server Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and third-party products that use this software, allows attackers to have an unknown impact via certain GIF images, related t | 2.2% | — |
| CVE-2019-1740 | HIGH 8.6 | cisco ios A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability are due to a parsing issue on | 2.2% | — |
| CVE-2018-0869 | MED 5.4 | microsoft sharepoint_enterprise_server SharePoint Server 2016 allows an elevation of privilege vulnerability due to how web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". | 2.2% | — |
| CVE-2011-4739 | HIGH 10.0 | parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demo | 2.2% | — |
| CVE-2011-4730 | HIGH 10.0 | parallels parallels_plesk_panel The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended works | 2.2% | — |
| CVE-2022-37981 | MED 4.3 | microsoft windows_10 Windows Event Logging Service Denial of Service Vulnerability | 2.2% | — |
| CVE-2016-4762 | HIGH 8.8 | apple icloud WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, iCloud before 6.0 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. | 2.2% | — |
| CVE-2012-4145 | HIGH 10.0 | opera opera_browser Unspecified vulnerability in Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, has unknown impact and attack vectors, related to a "low severity issue." | 2.2% | — |
| CVE-2017-11880 | MED 4.7 | microsoft windows_10 Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to run a specially crafted application and obtain informa | 2.2% | — |