57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-4372 | HIGH 8.8 | apple icloud Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8. | 2.1% | — |
| CVE-2010-4676 | MED 6.8 | cisco 5500_series_adaptive_security_appliance Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote authenticated users to cause a denial of service (device crash) via a high volume of IPsec traffic, aka Bug ID CSCsx52748. | 2.1% | — |
| CVE-2022-24473 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2020-9553 | LOW 3.3 | adobe bridge Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.1% | — |
| CVE-2024-29131 | HIGH 7.3 | apache commons_configuration Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. | 2.1% | — |
| CVE-2017-3154 | HIGH 7.5 | apache atlas Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information. | 2.1% | — |
| CVE-2012-0356 | HIGH 7.8 | cisco 5500_series_adaptive_security_appliance Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 7.0 through 7.2 before 7.2(5.7), 8.0 before 8.0(5.27), 8.1 before 8.1(2.53), 8.2 before 8.2(5.8), 8.3 before | 2.1% | — |
| CVE-2017-8712 | MED 5.3 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information D | 2.1% | — |
| CVE-2017-8711 | MED 5.3 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosu | 2.1% | — |
| CVE-2017-3155 | MED 6.1 | apache atlas Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting. | 2.1% | — |
| CVE-2001-0666 | LOW 2.1 | microsoft exchange_server Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox. | 2.1% | — |
| CVE-2023-31248 | HIGH 7.8 | canonical ubuntu_linux Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace | 2.1% | — |
| CVE-2022-46764 | CRIT 9.8 | trueconf server A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution. | 2.1% | — |
| CVE-2017-5658 | MED 5.3 | apache pony_mail The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derived information disclosure on private lists about the timing of specific email subjects or text bodies, | 2.1% | — |
| CVE-2017-0189 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows 10 when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode, aka "Win32k Elevatio | 2.1% | — |
| CVE-2016-4766 | HIGH 8.8 | apple iphone_os WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2 | 2.1% | — |
| CVE-2009-2975 | MED 5.0 | mozilla firefox Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value specifying a protocol associated with an external application, | 2.1% | — |
| CVE-2005-4258 | HIGH 7.8 | cisco catalyst Unspecified Cisco Catalyst Switches allow remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). NOTE: the provenance of this issue is unknown; the | 2.1% | — |
| CVE-2005-3809 | HIGH 7.8 | linux linux_kernel The nfattr_to_tcp function in ip_conntrack_proto_tcp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via an update message without private protocol information, which triggers a null dereference. | 2.1% | — |
| CVE-2026-26127 | HIGH 7.5 | microsoft .net Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network. | 2.0% | — |
| CVE-2020-17015 | MED 4.3 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 2.0% | — |
| CVE-2015-6388 | MED 5.0 | cisco unified_computing_system_central_software Cisco Unified Computing System (UCS) Central software 1.3(0.1) allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted request, aka Bug ID CSCux33575. | 2.0% | — |
| CVE-2015-0590 | MED 5.0 | cisco webex_meeting_center Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providing crafted parameters during a meeting-join action, aka Bug ID CSCuo34165. | 2.0% | — |
| CVE-2012-4094 | MED 5.4 | cisco unified_computing_system Buffer overflow in the Smart Call Home feature in the fabric interconnect in Cisco Unified Computing System (UCS) allows remote attackers to cause a denial of service by reading and forging control messages associated with Smart Call Home reports, aka Bug ID C | 2.0% | — |
| CVE-2016-9195 | MED 5.3 | cisco wireless_lan_controller A vulnerability in RADIUS Change of Authorization (CoA) request processing in the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition by disconnecting a single connection. This vulner | 2.0% | — |