IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-30142 HIGH 7.5 microsoft windows_10 Windows File History Remote Code Execution Vulnerability 2.1%
CVE-2024-38044 HIGH 7.2 microsoft windows_server_2012 DHCP Server Service Remote Code Execution Vulnerability 2.1%
CVE-2021-1579 HIGH 8.1 cisco application_policy_infrastructure_controller A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker with Administrator read-only credentials to 2.1%
CVE-2020-1172 MED 4.2 microsoft chakracore <p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An 2.1%
CVE-2019-1002 MED 4.2 microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 2.1%
CVE-2019-1814 HIGH 8.6 cisco sf300-08_firmware A vulnerability in the interactions between the DHCP and TFTP features for Cisco Small Business 300 Series (Sx300) Managed Switches could allow an unauthenticated, remote attacker to cause the device to become low on system memory, which in turn could lead to 2.1%
CVE-2019-1679 MED 5.0 cisco telepresence_conductor A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to trigger an HTTP request from an affected server to 2.1%
CVE-2022-25370 MED 5.4 apache ofbiz Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.05, and earlier versions, by leveraging a vulnerability in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id= 2.1%
CVE-2021-37150 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. 2.1%
CVE-2015-4199 HIGH 7.1 cisco ios Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause a denial of service (NULL pointer free and module crash) by triggering intermittent connectivity 2.1%
CVE-2002-0848 MED 5.0 cisco vpn_5000_concentrator_series_software Cisco VPN 5000 series concentrator hardware 6.0.21.0002 and earlier, and 5.2.23.0003 and earlier, when using RADIUS with a challenge type of Password Authentication Protocol (PAP) or Challenge, sends the user password in cleartext in a validation retry request 2.1%
CVE-2022-28249 MED 5.5 adobe acrobat Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory st 2.1%
CVE-2009-0627 HIGH 7.8 cisco nexus_5000 Unspecified vulnerability in Cisco NX-OS before 4.0(1a)N2(1), when running on Nexus 5000 platforms, allows remote attackers to cause a denial of service (crash) via an unspecified "sequence of TCP packets" related to "TCP State manipulation," possibly related 2.1%
CVE-2021-40111 MED 6.5 apache james In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP command could be used to trigger infinite loops resulting in expensive CPU computations and OutOfMemory exceptions. This can be used for a Denial 2.1%
CVE-2018-0454 HIGH 8.8 cisco cloud_services_platform_2100_firmware A vulnerability in the web-based management interface of Cisco Cloud Services Platform 2100 could allow an authenticated, remote attacker to perform command injection. The vulnerability is due to insufficient input validation of command input. An attacker coul 2.1%
CVE-2015-0649 HIGH 7.8 cisco ios Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) TCP packets, aka Bug ID CSCun63514. 2.1%
CVE-2023-33308 CRIT 9.8 fortinet fortios A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or com 2.1%
CVE-2022-26898 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability 2.1%
CVE-2021-31963 HIGH 7.1 microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability 2.1%
CVE-2020-17130 MED 6.5 microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability 2.1%
CVE-2023-29216 CRIT 9.8 apache linkis In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to configure a new data source to trigger a deserialization vulnerability, eventually leading to remote code executi 2.1%
CVE-2023-29215 CRIT 9.8 apache linkis In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulnerability and eventually lead to remote code execution. Theref 2.1%
CVE-2022-25169 MED 5.5 apache tika The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files. 2.1%
CVE-2021-28455 HIGH 8.8 microsoft 365_apps Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability 2.1%
CVE-2014-3095 LOW 3.5 ibm db2 The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted UNION clause in a subqu 2.1%