57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2003-0259 | MED 5.0 | cisco vpn_3000_concentrator_series_software Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet. | 2.1% | — |
| CVE-2017-7025 | HIGH 7.8 | apple icloud An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbi | 2.1% | — |
| CVE-2017-7024 | HIGH 7.8 | apple icloud An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbi | 2.1% | — |
| CVE-2017-7023 | HIGH 7.8 | apple icloud An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbi | 2.1% | — |
| CVE-2017-7022 | HIGH 7.8 | apple icloud An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbi | 2.1% | — |
| CVE-2010-2976 | HIGH 10.0 | cisco unified_wireless_network_solution_software The controller in Cisco Unified Wireless Network (UWN) Solution 7.x through 7.0.98.0 has (1) a default SNMP read-only community of public, (2) a default SNMP read-write community of private, and a value of "default" for the (3) SNMP v3 username, (4) SNMP v3 au | 2.1% | — |
| CVE-2022-38041 | HIGH 7.5 | microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability | 2.1% | — |
| CVE-2021-34468 | HIGH 7.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2019-19813 | MED 5.5 | canonical ubuntu_linux In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner in kernel | 2.1% | — |
| CVE-2018-1281 | MED 6.5 | apache mxnet The clustered setup of Apache MXNet allows users to specify which IP address and port the scheduler will listen on via the DMLC_PS_ROOT_URI and DMLC_PS_ROOT_PORT env variables. In versions older than 1.0.0, however, the MXNet framework will listen on 0.0.0.0 r | 2.1% | — |
| CVE-2017-2463 | HIGH 8.8 | apple icloud An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" c | 2.1% | — |
| CVE-2013-1122 | MED 5.0 | cisco nexus_7000 Cisco NX-OS on the Nexus 7000, when a certain Overlay Transport Virtualization (OTV) configuration is used, allows remote attackers to cause a denial of service (M1-Series module reload) via crafted packets, aka Bug ID CSCud15673. | 2.1% | — |
| CVE-2007-1212 | MED 6.6 | microsoft windows_2000 Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via a crafted Enhanced Metafile (EMF) image format file. | 2.1% | — |
| CVE-2020-3196 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust memory res | 2.1% | — |
| CVE-2018-11773 | CRIT 9.8 | apache virtual_computing_lab Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as an argument to the php built in function strtotime. This allows for an attack against the underlying implementat | 2.1% | — |
| CVE-2018-0271 | CRIT 9.8 | cisco digital_network_architecture_center A vulnerability in the API gateway of the Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and access critical services. The vulnerability is due to a failure to normalize URLs prior to se | 2.1% | — |
| CVE-2025-21369 | HIGH 8.8 | microsoft windows_10_1507 Microsoft Digest Authentication Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2025-21368 | HIGH 8.8 | microsoft windows_10_1507 Microsoft Digest Authentication Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2024-36522 | CRIT 9.8 | apache wicket The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untrusted source without validation. Users are recommended to upgrade to versions 10.1.0, 9.18.0 or 8.16.0, which fix t | 2.1% | — |
| CVE-2021-34497 | MED 6.8 | microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2020-1453 | HIGH 8.6 | microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP | 2.1% | — |
| CVE-2020-1452 | HIGH 8.6 | microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP | 2.1% | — |
| CVE-2018-1340 | HIGH 7.5 | apache guacamole Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's session token if unencrypted HTTP reque | 2.1% | — |
| CVE-2016-8752 | HIGH 7.5 | apache atlas Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img. | 2.1% | — |
| CVE-2013-6688 | MED 6.3 | cisco unified_communications_manager Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager (ELM) component in Cisco Unified Communications Manager 9.1(1) and earlier allows remote authenticated users to create arbitrary files via a crafted path, aka B | 2.1% | — |