IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2012-1511 MED 4.3 vmware view Cross-site scripting (XSS) vulnerability in View Manager Portal in VMware View before 4.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. 2.0%
CVE-2011-2581 MED 5.0 cisco nexus_3000 The ACL implementation in Cisco NX-OS 5.0(2) and 5.0(3) before 5.0(3)N2(1) on Nexus 5000 series switches, and NX-OS before 5.0(3)U1(2a) on Nexus 3000 series switches, does not properly handle comments in conjunction with deny statements, which allows remote at 2.0%
CVE-2006-4909 LOW 2.6 cisco guard_ddos_mitigation_appliance Cross-site scripting (XSS) vulnerability in Cisco Guard DDoS Mitigation Appliance before 5.1(6), when anti-spoofing is enabled, allows remote attackers to inject arbitrary web script or HTML via certain character sequences in a URL that are not properly handle 2.0%
CVE-2026-58289 CRIT 9.0 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 2.0%
CVE-2025-53506 HIGH 7.5 apache tomcat Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10 2.0%
CVE-2022-26918 HIGH 7.8 microsoft windows_10 Windows Fax Compose Form Remote Code Execution Vulnerability 2.0%
CVE-2022-26916 HIGH 7.8 microsoft windows_10 Windows Fax Compose Form Remote Code Execution Vulnerability 2.0%
CVE-2021-44040 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1. 2.0%
CVE-2020-9558 LOW 3.3 adobe bridge Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. 2.0%
CVE-2018-15369 MED 6.8 cisco ios A vulnerability in the TACACS+ client subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to 2.0%
CVE-2024-20654 HIGH 8.0 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 2.0%
CVE-2023-36423 HIGH 8.8 microsoft windows_10_1507 Microsoft Remote Registry Service Remote Code Execution Vulnerability 2.0%
CVE-2014-3270 MED 5.0 cisco ios_xr The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (process hang) via a malformed packet, aka Bug ID CSCul80924. 2.0%
CVE-2025-21268 MED 4.3 microsoft windows_10_1507 MapUrlToZone Security Feature Bypass Vulnerability 2.0%
CVE-2019-16921 HIGH 7.5 linux linux_kernel In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/infiniband/hw/hns/hns_roce_main.c does not initialize the resp data structure, which might allow attackers to obtain sensitive information from kernel stack memory, aka CID-df7e40425813. 2.0%
CVE-2019-6638 MED 6.5 f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, Malformed http requests made to an undisclosed iControl REST endpoint can lead to infinite loop of the restjavad process. 2.0%
CVE-2016-6805 MED 5.9 apache ignite Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents. 2.0%
CVE-2022-30973 MED 5.5 apache tika We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a 2.0%
CVE-2015-6341 MED 5.0 cisco wireless_lan_controller_software The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attackers to cause a denial of service (client disconnection) via unspecified vectors, aka Bug ID CSCuw10610. 2.0%
CVE-2015-7750 MED 5.0 juniper screenos The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3.0r18 before 6.3.0r18-dnc1, and 6.3.0r19 allows remote attackers to cause a denial of service via a crafted L2T 2.0%
CVE-2015-6334 MED 5.0 cisco asr_5000_software Cisco ASR 5000 and 5500 devices with software 18.0.0.57828 and 19.0.M0.61045 allow remote attackers to cause a denial of service (vpnmgr process restart) via a crafted header in a TACACS packet, aka Bug ID CSCuw01984. 2.0%
CVE-2015-4273 MED 5.0 cisco asr_5000_series_software The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 15.0(912), 15.0(935), and 15.0(938) allows remote attackers to cause a denial of service (Session Manager outage) via malformed fields in an IP packet, aka Bug ID CSCut 2.0%
CVE-2015-0765 MED 5.0 cisco ons_15454_system_software Cisco ONS 15454 System Software 10.30 and 10.301 allows remote attackers to cause a denial of service (tNetTask CPU consumption or card reset) via a flood of (1) IP or (2) Ethernet traffic, aka Bug ID CSCus57263. 2.0%
CVE-2015-0743 MED 5.0 cisco headend_digital_broadband_delivery_system Cisco Headend System Release allows remote attackers to cause a denial of service (DHCP and TFTP outage) via a flood of crafted UDP traffic, aka Bug ID CSCus04097. 2.0%
CVE-2012-1315 HIGH 7.8 cisco ios Memory leak in the SIP inspection feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit SIP traffic, aka Bug ID CSCti46171. 2.0%