57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-8515 | MED 5.5 | microsoft windows_10 Microsoft Windows 10 1511, 1607, and 1703, and Windows Server 2016 allow an unauthenticated attacker to send a specially crafted kernel mode request to cause a denial of service on the target system, aka "Windows VAD Cloning Denial of Service Vulnerability". | 1.8% | — |
| CVE-2015-1452 | HIGH 7.8 | fortinet fortios The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPWAP Access Controller) via a large number of ClientHello DTLS messages. | 1.8% | — |
| CVE-2014-0318 | HIGH 7.2 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly control acc | 1.8% | — |
| CVE-2024-43475 | HIGH 7.3 | microsoft windows_server_2008 Microsoft Windows Admin Center Information Disclosure Vulnerability | 1.8% | — |
| CVE-2022-20842 | CRIT 9.0 | cisco rv340_firmware Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information ab | 1.8% | — |
| CVE-2020-1327 | MED 6.1 | microsoft azure_devops_server A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'. | 1.8% | — |
| CVE-2019-1896 | HIGH 7.2 | cisco integrated_management_controller_supervisor A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of | 1.8% | — |
| CVE-2019-1676 | MED 6.8 | cisco meeting_server A vulnerability in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CMS) software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of the Cisco Meeting Server. The vulnerability is due t | 1.8% | — |
| CVE-2001-0502 | MED 4.6 | microsoft windows_2000 Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password o | 1.8% | — |
| CVE-2022-30215 | HIGH 7.5 | microsoft windows_server_2016 Active Directory Federation Services Elevation of Privilege Vulnerability | 1.8% | — |
| CVE-2020-16884 | MED 4.2 | microsoft edge <p>A remote code execution vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code i | 1.8% | — |
| CVE-2020-3363 | HIGH 8.6 | cisco sf200-24_firmware A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient | 1.8% | — |
| CVE-2020-8197 | HIGH 8.8 | citrix application_delivery_controller_firmware Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands. | 1.8% | — |
| CVE-2020-3191 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denia | 1.8% | — |
| CVE-2018-8638 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Information Disclosure Vulnerability." This affects Windows 10, Windows Server 2019. | 1.8% | — |
| CVE-2018-20002 | MED 5.5 | f5 traffix_signaling_delivery_controller The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service (memory consumption), as demonstrated b | 1.8% | — |
| CVE-2015-0621 | HIGH 7.8 | cisco telepresence_mcu_4500_series_software Cisco TelePresence MCU devices with software 4.5(1.45) allow remote attackers to cause a denial of service (device reload) via an unspecified series of TCP packets, aka Bug ID CSCur50347. | 1.8% | — |
| CVE-2015-0592 | HIGH 7.8 | cisco ios The Zone-Based Firewall implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted network traffic that triggers incorrect kernel-timer handling, aka Bug ID CSCuh25672. | 1.8% | — |
| CVE-2014-6378 | HIGH 7.8 | juniper junos Juniper Junos 11.4 before R12-S4, 12.1X44 before D35, 12.1X45 before D30, 12.1X46 before D25, 12.1X47 before D10, 12.2 before R9, 12.2X50 before D70, 12.3 before R7, 13.1 before R4 before S3, 13.1X49 before D55, 13.1X50 before D30, 13.2 before R5, 13.2X50 befo | 1.8% | — |
| CVE-2014-6377 | HIGH 7.8 | juniper junos_e Juniper JunosE before 13.3.3p0-1, 14.x before 14.3.2, and 15.x before 15.1.0, when DEBUG severity icmpTraffic logging is enabled, allows remote attackers to cause a denial of service (SRP reset) via a crafted ICMP packet to the (1) interface or (2) loopback IP | 1.8% | — |
| CVE-2013-1103 | HIGH 7.8 | cisco 2000_wireless_lan_controller Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allow remote attackers to cause a denial of service (Access Point reload) via crafted SIP packets, aka Bug ID CSCts87659. | 1.8% | — |
| CVE-2013-1102 | HIGH 7.8 | cisco 2000_wireless_lan_controller The Wireless Intrusion Prevention System (wIPS) component on Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.0, 7.1 and 7.2 before 7.2.110.0, and 7.3 before 7.3.101.0 allows remote attackers to cause a denial of service (device rel | 1.8% | — |
| CVE-2010-0415 | MED 4.6 | linux linux_kernel The do_pages_move function in mm/migrate.c in the Linux kernel before 2.6.33-rc7 does not validate node values, which allows local users to read arbitrary kernel memory locations, cause a denial of service (OOPS), and possibly have unspecified other impact by | 1.8% | — |
| CVE-2009-3282 | HIGH 7.8 | vmware fusion Integer overflow in the vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 allows host OS users to cause a denial of service to the host OS via unspecified vectors. | 1.8% | — |
| CVE-2008-2637 | MED 4.3 | f5 firepass_ssl_vpn Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN 6.0.2 hotfix 3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via quotes in (1) the css_exceptions parameter in vdesk/admincon/webyfiers.p | 1.8% | — |