57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-21984 | CRIT 9.8 | vmware vrealize_business_for_cloud VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious actor with network access may exploit this issue causing unauthorised remote code execution on vRealize Business | 2.0% | — |
| CVE-2020-5903 | MED 6.1 | f5 big-ip_access_policy_manager In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. | 2.0% | — |
| CVE-2022-35774 | MED 4.9 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2021-43255 | MED 5.5 | microsoft 365_apps Microsoft Office Trust Center Spoofing Vulnerability | 2.0% | — |
| CVE-2024-21307 | HIGH 7.5 | microsoft windows_10_1507 Remote Desktop Client Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2022-35744 | CRIT 9.8 | microsoft windows_10_1507 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2022-20801 | MED 4.7 | cisco rv340_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. Thes | 2.0% | — |
| CVE-2018-8165 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 | 2.0% | — |
| CVE-2023-33170 | HIGH 8.1 | fedoraproject fedora ASP.NET and Visual Studio Security Feature Bypass Vulnerability | 2.0% | — |
| CVE-2023-21728 | HIGH 7.5 | microsoft windows_10_1607 Windows Netlogon Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-21683 | HIGH 7.5 | microsoft windows_10_1607 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-21677 | HIGH 7.5 | microsoft windows_10_1607 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-21527 | HIGH 7.5 | microsoft windows_10_1607 Windows iSCSI Service Denial of Service Vulnerability | 2.0% | — |
| CVE-2022-23206 | HIGH 7.5 | apache traffic_control In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach. | 2.0% | — |
| CVE-2021-33746 | HIGH 8.0 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-1639 | HIGH 7.0 | microsoft visual_studio_2017 Visual Studio Code Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2016-1295 | MED 5.3 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775. | 2.0% | — |
| CVE-2010-1729 | MED 4.3 | apple safari WebKit.dll in WebKit, as used in Safari.exe 4.531.9.1 in Apple Safari, allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop. | 2.0% | — |
| CVE-2008-3817 | HIGH 7.8 | cisco adaptive_security_appliance_5500_series Memory leak in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 8.0 before 8.0(4) and 8.1 before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via an unspecified sequence of packets, related to | 2.0% | — |
| CVE-2008-3811 | HIGH 7.8 | cisco ios Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabled, allows remote attackers to cause a denial of service (device reload) via segmented SCCP messages, aka Cisco Bug ID CSCsi17020, a different vulnerability tha | 2.0% | — |
| CVE-2007-5584 | HIGH 7.8 | cisco firewall_services_module Unspecified vulnerability in Cisco Firewall Services Module (FWSM) 3.2(3) allows remote attackers to cause a denial of service (device reload) via crafted "data in the control-plane path with Layer 7 Application Inspections." | 2.0% | — |
| CVE-2007-5537 | HIGH 7.8 | cisco unified_callmanager Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote attackers to cause a denial of service (kernel panic) via a flood of SIP INVITE messages to UDP port 5060, which triggers resource ex | 2.0% | — |
| CVE-2007-4789 | HIGH 7.8 | cisco content_switching_module_with_ssl Cisco Content Switching Modules (CSM) 4.2 before 4.2.7, and Cisco Content Switching Module with SSL (CSM-S) 2.1 before 2.1.6, when service termination is enabled, allow remote attackers to cause a denial of service (reboot) via unspecified vectors related to h | 2.0% | — |
| CVE-2007-4788 | HIGH 7.8 | cisco content_switching_module_with_ssl Cisco Content Switching Modules (CSM) 4.2 before 4.2.3a, and Cisco Content Switching Module with SSL (CSM-S) 2.1 before 2.1.2a, allow remote attackers to cause a denial of service (CPU consumption or reboot) via sets of out-of-order TCP packets with unspecifie | 2.0% | — |
| CVE-2007-3923 | HIGH 7.8 | cisco wide_area_application_services The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the NM-WAE-502 network module, when Edge Services are configured, allows remote attackers to cause a denial o | 2.0% | — |