IT
57.061 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.061 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2010-0026 MED 4.0 microsoft windows_server_2008 The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, aka " 1.6%
CVE-2022-41127 HIGH 8.5 microsoft dynamics_365_business_central Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability 1.6%
CVE-2019-19916 MED 6.1 midori-browser midori In Midori Browser 0.5.11 (on Windows 10), Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the multipart/x-mixed-replace MIME type. This could result in script running where CSP should have blocked it, allowing 1.6%
CVE-2019-1984 MED 6.5 cisco enterprise_network_function_virtualization_infrastructure_sofware A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite files on the underlying operating system (OS) of an affected device. T 1.6%
CVE-2019-0996 MED 6.5 microsoft azure_devops_server A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery. An attacker who successfully exploited this vulnerability could bypass OAuth protections and regist 1.6%
CVE-2019-0033 HIGH 7.5 juniper junos A firewall bypass vulnerability in the proxy ARP service of Juniper Networks Junos OS allows an attacker to cause a high CPU condition leading to a Denial of Service (DoS). This issue affects only IPv4. Affected releases are Juniper Networks Junos OS: 12.1X46 1.6%
CVE-2013-5488 MED 5.0 cisco prime_lan_management_solution Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS), Cisco Security Manager, Cisco Unified Service Monitor, and Cisco Unified Operations Manager, does not properly interact with the ActiveMQ component, which allows remote attackers to c 1.6%
CVE-2013-0253 MED 5.8 apache maven The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack. 1.6%
CVE-2024-49082 MED 6.8 microsoft windows_10_1507 Windows File Explorer Information Disclosure Vulnerability 1.6%
CVE-2024-50306 CRIT 9.1 apache traffic_server Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes t 1.6%
CVE-2024-38214 MED 6.5 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability 1.6%
CVE-2021-28478 HIGH 7.6 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 1.6%
CVE-2019-0020 CRIT 10.0 juniper advanced_threat_prevention Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3. 1.6%
CVE-2016-0215 MED 6.5 ibm db2 IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the AVG OLAP function on an Oracle compatibl 1.6%
CVE-2009-2119 MED 4.3 f5 firepass_ssl_vpn Cross-site scripting (XSS) vulnerability in the login interface (my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2 and 6.0 through 6.0.3 allows remote attackers to inject arbitrary web script or HTML via a base64-encoded xcho parameter. 1.6%
CVE-2007-5582 MED 4.3 cisco ciscoworks_server Cross-site scripting (XSS) vulnerability in the login page in Cisco CiscoWorks Server (CS), possibly 2.6 and earlier, when using CiscoWorks Common Services 3.0.x and 3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. 1.6%
CVE-2007-4284 MED 4.3 cisco meetingplace_web_confrencing Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified MeetingPlace Web Conferencing (MP) 5.3.235.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) Success Template (STPL) and (2) Failure Template (FTPL) par 1.6%
CVE-2023-36543 MED 6.5 apache airflow Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is recommended to upgrade to a version that is not affected 1.6%
CVE-2023-23388 HIGH 8.8 microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability 1.6%
CVE-2022-37425 CRIT 9.9 opennebula opennebula Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion. 1.6%
CVE-2020-1617 HIGH 7.5 juniper junos This issue occurs on Juniper Networks Junos OS devices which do not support Advanced Forwarding Interface (AFI) / Advanced Forwarding Toolkit (AFT). Devices using AFI and AFT are not exploitable to this issue. An improper initialization of memory in the packet 1.6%
CVE-2022-45136 CRIT 9.8 apache jena_sdb Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver in particular is known to be vulnerab 1.6%
CVE-2022-30170 HIGH 7.3 microsoft windows_10 Windows Credential Roaming Service Elevation of Privilege Vulnerability 1.6%
CVE-2019-6616 HIGH 7.2 f5 big-ip_access_policy_manager On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, administrative users with TMSH access can overwrite critical system files on BIG-IP which can result in bypass of whitelist / blacklist restrictions enforced by appl 1.6%
CVE-2017-2312 MED 6.5 juniper junos On Juniper Networks devices running Junos OS affected versions and with LDP enabled, a specific LDP packet destined to the RE (Routing Engine) will consume a small amount of the memory allocated for the rpd (routing protocol daemon) process. Over time, repeate 1.6%