57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2012-1314 | HIGH 7.8 | cisco ios The WAAS Express feature in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit traffic, aka Bug ID CSCtt45381. | 2.0% | — |
| CVE-2012-1311 | HIGH 7.8 | cisco ios The RSVP feature in Cisco IOS 15.0 and 15.1 and IOS XE 3.2.xS through 3.4.xS before 3.4.2S, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge and service outage) via crafted RSVP packets, aka Bug ID | 2.0% | — |
| CVE-2012-0387 | HIGH 7.8 | cisco ios Memory leak in the HTTP Inspection Engine feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit HTTP traffic, aka Bug ID CSCtq36 | 2.0% | — |
| CVE-2012-0383 | HIGH 7.8 | cisco ios Memory leak in the NAT feature in Cisco IOS 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (memory consumption, and device hang or reload) via SIP packets that require translation, related to a "memory starvation vulnerability," aka | 2.0% | — |
| CVE-2022-20723 | MED 5.5 | cisco ios_xe Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system | 2.0% | — |
| CVE-2015-2839 | MED 4.3 | citrix netscaler The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the file_name JSON member in params/xen_hotfix/0 to nitro | 2.0% | — |
| CVE-2024-30311 | MED 5.5 | adobe acrobat Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Expl | 2.0% | — |
| CVE-2023-28241 | HIGH 7.5 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability | 2.0% | — |
| CVE-2019-1967 | HIGH 7.5 | cisco nx-os A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to excessive use of system resources | 2.0% | — |
| CVE-2019-1964 | HIGH 8.6 | cisco nx-os A vulnerability in the IPv6 traffic processing of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an unexpected restart of the netstack process on an affected device. The vulnerability is due to improper validation of IPv6 traffic | 2.0% | — |
| CVE-2019-6233 | HIGH 8.8 | apple icloud A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code exec | 2.0% | — |
| CVE-2017-6613 | MED 5.8 | cisco prime_network_registrar A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause the DNS process to momentarily restart, which could lead to a partial denial of service (DoS) condition on the affected | 2.0% | — |
| CVE-2014-2113 | HIGH 7.8 | cisco ios Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to cause a denial of service (I/O memory consumption and device reload) via a malformed IPv6 packet, aka Bug ID CS | 2.0% | — |
| CVE-2003-1106 | MED 5.0 | The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute. | 2.0% | — |
| CVE-2002-2150 | MED 5.0 | juniper netscreen_screenos Firewalls from multiple vendors empty state tables more slowly than they are filled, which allows remote attackers to flood state tables with packet flooding attacks such as (1) TCP SYN flood, (2) UDP flood, or (3) Crikey CRC Flood, which causes the firewall t | 2.0% | — |
| CVE-2023-33129 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-29369 | MED 6.5 | microsoft windows_server_2012 Remote Procedure Call Runtime Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-24938 | MED 6.5 | microsoft windows_10_1809 Windows CryptoAPI Denial of Service Vulnerability | 2.0% | — |
| CVE-2022-25763 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. | 2.0% | — |
| CVE-2021-1223 | HIGH 7.5 | cisco ios_xe Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An a | 2.0% | — |
| CVE-2016-1349 | HIGH 7.5 | cisco ios_xe The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410. | 2.0% | — |
| CVE-2015-1210 | MED 5.0 | canonical ubuntu_linux The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly consider fr | 2.0% | — |
| CVE-2008-0028 | HIGH 7.1 | cisco adaptive_security_appliance_software Unspecified vulnerability in Cisco PIX 500 Series Security Appliance and 5500 Series Adaptive Security Appliance (ASA) before 7.2(3)6 and 8.0(3), when the Time-to-Live (TTL) decrement feature is enabled, allows remote attackers to cause a denial of service (de | 2.0% | — |
| CVE-2026-23795 | MED 4.9 | apache syncope Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with adequate entitlements to create or edit Keymaster parameters via Console can construct malicious XML text to launch an XXE attack, thereby caus | 2.0% | — |
| CVE-2020-4952 | HIGH 8.8 | ibm security_guardium IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper access control. IBM X-Force ID: 192028. | 2.0% | — |