57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-11849 | MED 4.7 | microsoft windows_10 Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially | 2.2% | — |
| CVE-2017-11842 | MED 4.7 | microsoft windows_10 Windows kernel in Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted application due to the Windows kernel impr | 2.2% | — |
| CVE-2011-4348 | HIGH 7.1 | linux linux_kernel Race condition in the sctp_rcv function in net/sctp/input.c in the Linux kernel before 2.6.29 allows remote attackers to cause a denial of service (system hang) via SCTP packets. NOTE: in some environments, this issue exists because of an incomplete fix for C | 2.2% | — |
| CVE-2023-36723 | HIGH 7.8 | microsoft windows_10_1809 Windows Container Manager Service Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2021-42294 | HIGH 7.2 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2017-12214 | HIGH 8.8 | cisco unified_customer_voice_portal A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is | 2.2% | — |
| CVE-2024-21756 | HIGH 8.8 | fortinet fortisandbox A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized | 2.2% | — |
| CVE-2019-18909 | HIGH 8.0 | hp thinpro The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges. | 2.2% | — |
| CVE-2016-7221 | HIGH 7.8 | microsoft windows_10 Input Method Editor (IME) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 mishandles DLL loading, which al | 2.2% | — |
| CVE-2020-3131 | MED 6.5 | cisco webex_teams A vulnerability in the Cisco Webex Teams client for Windows could allow an authenticated, remote attacker to cause the client to crash, resulting in a denial of service (DoS) condition. The attacker needs a valid developer account to exploit this vulnerability | 2.2% | — |
| CVE-2007-5568 | HIGH 7.1 | cisco adaptive_security_appliance_software Cisco PIX and ASA appliances with 7.0 through 8.0 software, and Cisco Firewall Services Module (FWSM) 3.1(5) and earlier, allow remote attackers to cause a denial of service (device reload) via a crafted MGCP packet, aka CSCsi90468 (appliance) and CSCsi00694 ( | 2.2% | — |
| CVE-2022-26907 | MED 5.3 | microsoft azure_sdk_for_.net Azure SDK for .NET Information Disclosure Vulnerability | 2.2% | — |
| CVE-2019-17658 | CRIT 9.8 | fortinet forticlient An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path. | 2.2% | — |
| CVE-2016-1302 | HIGH 8.8 | cisco nx-os Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RB | 2.2% | — |
| CVE-2024-24916 | MED 6.5 | checkpoint smartconsole Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin). | 2.2% | — |
| CVE-2017-15805 | HIGH 7.5 | cisco small_business_sa520_firmware Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files. | 2.2% | — |
| CVE-2018-0432 | HIGH 8.8 | cisco vedge_1000_firmware A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included | 2.2% | — |
| CVE-2017-5029 | HIGH 8.8 | debian debian_linux The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a r | 2.2% | — |
| CVE-2011-2584 | HIGH 7.5 | cisco show_and_share Cisco Show and Share 5(2), 5.2(1), and 5.2(2) before 5.2(2.1) allows remote attackers to access the (1) Encoders and Pull Configurations, (2) Push Configurations, (3) Video Encoding Formats, and (4) Transcoding administration pages, and cause a denial of servi | 2.2% | — |
| CVE-2010-0686 | HIGH 7.5 | vmware esx_server WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability. | 2.2% | — |
| CVE-2025-29814 | CRIT 9.3 | microsoft partner_center Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. | 2.2% | — |
| CVE-2024-21348 | HIGH 7.5 | microsoft windows_10_1507 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 2.2% | — |
| CVE-2021-42279 | MED 4.2 | microsoft windows_10 Chakra Scripting Engine Memory Corruption Vulnerability | 2.2% | — |
| CVE-2019-5618 | HIGH 7.8 | a-pdf wav_to_mp3 A-PDF WAV to MP3 version 1.0.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow. | 2.2% | — |
| CVE-2002-0720 | HIGH 7.2 | microsoft windows_2000 A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code. | 2.2% | — |