57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36907 | MED 5.5 | microsoft windows_10 Windows Cryptographic Services Information Disclosure Vulnerability | 1.7% | — |
| CVE-2023-36905 | MED 5.5 | microsoft windows_10 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | 1.7% | — |
| CVE-2015-6427 | MED 5.0 | cisco firesight_system_software Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL session that is mishandled after decryption, aka Bug ID CSCux53437. | 1.7% | — |
| CVE-2015-0669 | MED 6.4 | cisco ios The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 15.4S and 15.4(3)S allows remote attackers to modify configuration settings or cause a denial of service (partial service outage) by sending crafted Autonomic Networking (AN) messages on | 1.7% | — |
| CVE-2012-1340 | MED 5.0 | cisco mds_9000_nx-os The Fibre Channel over IP (FCIP) implementation in Cisco MDS NX-OS 4.2 and 5.2 on MDS 9000 series switches allows remote attackers to cause a denial of service (module reload) via a crafted FCIP header, aka Bug ID CSCtn93151. | 1.7% | — |
| CVE-2022-35724 | HIGH 7.5 | apache avro It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro versio | 1.7% | — |
| CVE-2022-32223 | HIGH 7.3 | nodejs node.js Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files | 1.7% | — |
| CVE-2021-43214 | HIGH 7.8 | microsoft raw_image_extension Web Media Extensions Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2020-4271 | MED 6.3 | ibm qradar_security_information_and_event_manager IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower privileged user. IBM X-ForceID: 175897. | 1.7% | — |
| CVE-2017-1519 | MED 5.9 | ibm db2 IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a particular configuration. IBM X-Force ID: 129829. | 1.7% | — |
| CVE-2012-0005 | MED 6.9 | microsoft windows_server_2003 The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2, when a Chinese, Japanese, or Korean system locale is used, can access uninitialized memory during the | 1.7% | — |
| CVE-2006-3073 | LOW 2.6 | cisco asa_5500 Multiple cross-site scripting (XSS) vulnerabilities in the WebVPN feature in the Cisco VPN 3000 Series Concentrators and Cisco ASA 5500 Series Adaptive Security Appliances (ASA), when in WebVPN clientless mode, allow remote attackers to inject arbitrary web sc | 1.7% | — |
| CVE-2004-2527 | MED 5.4 | The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Windows | 1.7% | — |
| CVE-2023-28234 | HIGH 7.5 | microsoft windows_11_21h2 Windows Secure Channel Denial of Service Vulnerability | 1.7% | — |
| CVE-2023-28233 | HIGH 7.5 | microsoft windows_11_21h2 Windows Secure Channel Denial of Service Vulnerability | 1.7% | — |
| CVE-2018-15447 | MED 6.5 | cisco integrated_management_controller A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied inpu | 1.7% | — |
| CVE-2018-1108 | MED 5.9 | canonical ubuntu_linux kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated. | 1.7% | — |
| CVE-2016-1264 | HIGH 8.8 | juniper junos Race condition in the Op command in Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 12.3X50 before 12.3X50-D50, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D39, 13.2X5 | 1.7% | — |
| CVE-2014-2155 | MED 5.0 | cisco cns_network_registrar The DHCPv6 server module in Cisco CNS Network Registrar 7.1 allows remote attackers to cause a denial of service (daemon reload) via a malformed DHCPv6 packet, aka Bug ID CSCuo07437. | 1.7% | — |
| CVE-2026-50652 | HIGH 7.5 | microsoft .net_framework Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. | 1.7% | — |
| CVE-2024-41937 | MED 6.1 | apache airflow Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web s | 1.7% | — |
| CVE-2024-21420 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2023-36407 | HIGH 7.8 | microsoft windows_11_21h2 Windows Hyper-V Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2020-35769 | CRIT 9.8 | webmin webmin miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program. | 1.7% | — |
| CVE-2019-15666 | MED 4.4 | debian debian_linux An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory validation. | 1.7% | — |