IT
57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.057 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-33166 MED 6.5 microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability 1.6%
CVE-2023-32035 MED 6.5 microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability 1.6%
CVE-2023-32034 MED 6.5 microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability 1.6%
CVE-2020-3498 MED 6.5 cisco jabber A vulnerability in Cisco Jabber software could allow an authenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending special 1.6%
CVE-2015-5327 MED 6.5 linux linux_kernel Out-of-bounds memory read in the x509_decode_time function in x509_cert_parser.c in Linux kernels 4.3-rc1 and after. 1.6%
CVE-2016-1338 MED 6.5 cisco telepresence_video_communication_server_software Cisco TelePresence Video Communication Server (VCS) X8.5.1 and X8.5.2 allows remote authenticated users to cause a denial of service (VoIP outage) via a crafted SIP message, aka Bug ID CSCuu43026. 1.6%
CVE-2015-0694 MED 5.0 cisco asr_9001 Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restrictions by using an address that was not supposed to have bee 1.6%
CVE-2015-0667 MED 5.0 cisco content_services_switch_11500_firmware The Management Interface on Cisco Content Services Switch (CSS) 11500 devices 8.20.4.02 and earlier allows remote attackers to bypass intended restrictions on local-network device access via crafted SSH packets, aka Bug ID CSCut14855. 1.6%
CVE-2003-1590 MED 5.0 sun one_web_server Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 6.0 SP3 through SP5 on Windows allows remote attackers to cause a denial of service (daemon crash) via unknown vectors. 1.6%
CVE-2009-1560 HIGH 7.8 cisco wvc54gc The Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 stores passwords and wireless-network keys in cleartext in (1) pass_wd.htm and (2) Wsecurity.htm, which allows remote attackers to obtain sensitive information by reading the HT 1.6%
CVE-2026-45454 MED 6.5 microsoft sharepoint_server Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.6%
CVE-2026-25166 HIGH 7.8 microsoft windows_10_1607 Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally. 1.6%
CVE-2025-27472 MED 5.4 microsoft windows_10_1507 Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. 1.6%
CVE-2023-35319 MED 6.5 microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability 1.6%
CVE-2023-35318 MED 6.5 microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability 1.6%
CVE-2023-35314 MED 6.5 microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability 1.6%
CVE-2023-33164 MED 6.5 microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability 1.6%
CVE-2022-25139 CRIT 9.8 f5 njs njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled. 1.6%
CVE-2021-1508 CRIT 9.8 cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthor 1.6%
CVE-2021-1505 CRIT 9.8 cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthor 1.6%
CVE-2018-4398 HIGH 7.5 apple icloud An issue existed in the method for determining prime numbers. This issue was addressed by using pseudorandom bases for testing of primes. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1, iTunes 12.9.1, iCloud for Wi 1.6%
CVE-2018-0160 MED 6.3 cisco ios_xe A vulnerability in Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of memory resources, ref 1.6%
CVE-2013-2321 MED 4.3 hp service_manager_web_tier Cross-site scripting (XSS) vulnerability in HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. 1.6%
CVE-2007-4011 HIGH 7.1 cisco wireless_lan_controller_software Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software before 3.2 20070727, 4.0 before 20070727, and 4.1 before 4.1.180.0 allows remote attackers to cause a denial of service (traffic amplification or ARP storm) 1.6%
CVE-2001-0622 HIGH 7.5 cisco content_services_switch_11000 The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through the inter 1.6%