57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-0719 | HIGH 7.8 | cisco ips_sensor_software The control-plane access-list implementation in Cisco IPS Software before 7.1(8p2)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of service (MainApp process outage) via crafted packets to TCP port 7000, aka Bug ID CSCui67394. | 1.6% | — |
| CVE-2010-0147 | MED 6.5 | cisco security_agent SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | 1.6% | — |
| CVE-2003-0677 | MED 5.0 | cisco webns Cisco CSS 11000 routers on the CS800 chassis allow remote attackers to cause a denial of service (CPU consumption or reboot) via a large number of TCP SYN packets to the circuit IP address, aka "ONDM Ping failure." | 1.6% | — |
| CVE-2024-48996 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-48995 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-48994 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-48993 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-43462 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-43459 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-38255 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2021-36186 | HIGH 8.8 | fortinet fortiweb A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests | 1.6% | — |
| CVE-2007-1382 | MED 6.8 | php com_extensions The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP's safe mode. | 1.6% | — |
| CVE-2025-59789 | HIGH 7.5 | apache brpc Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all platforms allows remote attackers to make the server crash via sending deep recursive json data. Root Cause: The bRPC json2pb component uses rapidjson to parse json data | 1.6% | — |
| CVE-2024-38062 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 1.6% | — |
| CVE-2021-1415 | MED 6.3 | cisco rv340_firmware Multiple vulnerabilities in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code with elevated privileges equivalent to the web service | 1.6% | — |
| CVE-2021-1413 | MED 6.3 | cisco rv340_firmware Multiple vulnerabilities in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code with elevated privileges equivalent to the web service | 1.6% | — |
| CVE-2020-16946 | HIGH 8.7 | microsoft sharepoint_designer <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially | 1.6% | — |
| CVE-2020-3365 | MED 4.3 | cisco enterprise_nfv_infrastructure_software A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a directory traversal attack on a limited set of restricted directories. The vulnerability is due to a | 1.6% | — |
| CVE-2018-0964 | MED 6.1 | microsoft windows_10 An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability." This affects Windows 10, | 1.6% | — |
| CVE-2018-0957 | MED 5.3 | microsoft windows_10 An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability." This affects Windows Ser | 1.6% | — |
| CVE-2002-1553 | HIGH 7.5 | cisco optical_networking_systems_software Cisco ONS15454 and ONS15327 running ONS before 3.4 allows remote attackers to modify the system configuration and delete files by establishing an FTP connection to the TCC, TCC+ or XTC using a username and password that does not exist. | 1.6% | — |
| CVE-2002-1190 | HIGH 7.5 | cisco unity_server Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls. | 1.6% | — |
| CVE-2002-0778 | HIGH 7.5 | cisco cache_engine_505 The default configuration of the proxy for Cisco Cache Engine and Content Engine allows remote attackers to use HTTPS to make TCP connections to allowed IP addresses while hiding the actual source IP. | 1.6% | — |
| CVE-2001-0455 | HIGH 7.5 | cisco aironet_340 Cisco Aironet 340 Series wireless bridge before 8.55 does not properly disable access to the web interface, which allows remote attackers to modify its configuration. | 1.6% | — |
| CVE-2024-37327 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |