IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2015-0725 HIGH 7.8 cisco videoscape_distribution_suite_for_internet_streaming Cisco Videoscape Distribution Suite Service Broker (aka VDS-SB), when a VDSM configuration on UCS is used, and Videoscape Distribution Suite for Internet Streaming (aka VDS-IS or CDS-IS) before 3.3.1 R7 and 4.x before 4.0.0 R4 allow remote attackers to cause a 1.9%
CVE-2023-36401 HIGH 7.2 microsoft windows_10_1507 Microsoft Remote Registry Service Remote Code Execution Vulnerability 1.9%
CVE-2018-1274 HIGH 7.5 broadcom spring_data_commons Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against 1.9%
CVE-2010-3939 HIGH 7.2 microsoft windows_2003_server Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via vectors related to 1.9%
CVE-2008-5542 HIGH 9.3 sunbeltsoftware vipre Sunbelt VIPRE 3.1.1832.2 and possibly 3.1.1633.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1 1.9%
CVE-2008-5540 HIGH 9.3 secure_computing secure_web_gateway Secure Computing Secure Web Gateway (aka Webwasher), when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have 1.9%
CVE-2008-5538 HIGH 9.3 prevx prevx1 Prevx Prevx1 2, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extensi 1.9%
CVE-2008-5524 HIGH 9.3 quickheal cat_quickheal CAT-QuickHeal 10.00 and possibly 9.50, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extens 1.9%
CVE-2023-22273 HIGH 7.2 adobe robohelp_server Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to Remote Code Execution by an admin authenticated attacker. Exploitation of this is 1.9%
CVE-2022-41042 HIGH 7.4 microsoft visual_studio_code Visual Studio Code Information Disclosure Vulnerability 1.9%
CVE-2017-5206 CRIT 9.0 firejail_project firejail Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a seccomp-based sandbox protection mechanism via the --allow-debuggers argument. 1.9%
CVE-2015-0754 HIGH 7.5 cisco finesse Cisco Finesse 10.5(1) allows remote authenticated users to obtain sensitive information or cause a denial of service (CPU and memory consumption) via a crafted XML document, aka Bug ID CSCut95810. 1.9%
CVE-2014-0682 MED 4.9 cisco webex_meetings_server Cisco WebEx Meetings Server allows remote authenticated users to bypass authorization checks and (1) join arbitrary meetings, or (2) terminate a meeting without having a host role, via a crafted URL, aka Bug ID CSCuj42346. 1.9%
CVE-2006-1357 MED 4.3 f5 firepass_4100 Cross-site scripting (XSS) vulnerability in my.support.php3 in F5 Firepass 4100 SSL VPN 5.4.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter. 1.9%
CVE-2023-32011 HIGH 7.5 microsoft windows_10_1507 Windows iSCSI Discovery Service Denial of Service Vulnerability 1.9%
CVE-2023-28217 HIGH 7.5 microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability 1.9%
CVE-2021-44549 HIGH 7.4 apache sling_commons_messaging_mail Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "man in the middle" attacks additional server identity checks must be performed when accessing mail servers. For 1.9%
CVE-2020-2012 HIGH 7.5 paloaltonetworks pan-os Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panorama management interface to read arbitrary files on the system 1.9%
CVE-2020-3179 HIGH 7.5 cisco asa_5505_firmware A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vul 1.9%
CVE-2017-3827 MED 5.8 cisco email_security_appliance_firmware A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters 1.9%
CVE-2021-3013 CRIT 9.8 ripgrep_project ripgrep ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working directory via the -z/--search-zip or --pre flag. 1.9%
CVE-2019-1197 MED 4.2 microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 1.9%
CVE-2019-1196 MED 4.2 microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 1.9%
CVE-2019-1139 MED 4.2 microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 1.9%
CVE-2007-5090 HIGH 7.5 ibm rational_clearquest Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt data via unspecified vectors. 1.9%