57.061 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.061 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-20128 | MED 5.3 | cisco secure_endpoint A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow i | 1.6% | — |
| CVE-2019-17656 | MED 5.4 | fortinet fortios A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiProxy 1.0.x, 1.1.x, 1.2.9 and below, 2.0.0 and below may allow an authenticated remote attacker to crash the service by sending a malformed PU | 1.6% | — |
| CVE-2016-9793 | HIGH 7.8 | linux linux_kernel The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified oth | 1.6% | — |
| CVE-2020-3441 | MED 5.3 | cisco webex_meetings A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to view sensitive information from the meeting room lobby. This vulnerability is due to insufficient protection of sensitive participant inf | 1.6% | — |
| CVE-2020-1454 | MED 5.4 | microsoft sharepoint_enterprise_server This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePo | 1.6% | — |
| CVE-2020-1326 | MED 5.4 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'. | 1.6% | — |
| CVE-2020-3235 | HIGH 7.7 | cisco ios A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerab | 1.6% | — |
| CVE-2019-12704 | MED 6.5 | cisco spa112_firmware A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to view the contents of arbitrary files on an affected device. The vulnerability is due to improper inpu | 1.6% | — |
| CVE-2017-12267 | MED 5.3 | cisco virtual_wide_area_application_services A vulnerability in the Independent Computing Architecture (ICA) accelerator feature for the Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an ICA application optimization-related process to restart, resulti | 1.6% | — |
| CVE-2017-8627 | MED 4.7 | microsoft windows_10 Windows Subsystem for Linux in Windows 10 1703, allows a denial of service vulnerability due to the way it handles objects in memory, aka "Windows Subsystem for Linux Denial of Service Vulnerability". | 1.6% | — |
| CVE-2017-7012 | HIGH 8.8 | apple icloud An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit Web Inspector" component | 1.6% | — |
| CVE-2017-0613 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first require | 1.6% | — |
| CVE-2016-1484 | HIGH 7.5 | cisco webex_meetings_server Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspecified vectors, aka Bug ID CSCuy92724. | 1.6% | — |
| CVE-2025-47171 | MED 6.7 | microsoft 365_apps Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. | 1.6% | — |
| CVE-2025-21301 | MED 6.5 | microsoft windows_10_1507 Windows Geolocation Service Information Disclosure Vulnerability | 1.6% | — |
| CVE-2023-50298 | HIGH 7.5 | apache solr Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a | 1.6% | — |
| CVE-2022-31705 | HIGH 8.2 | vmware esxi VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's | 1.6% | — |
| CVE-2020-4771 | MED 5.3 | ibm spectrum_protect_operations_center IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication of a websocket endpoint. By using known tools to subscribe to the webs | 1.6% | — |
| CVE-2017-8675 | HIGH 7.0 | microsoft windows_10 The Windows Kernel-Mode Drivers component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privil | 1.6% | — |
| CVE-2026-41293 | CRIT 9.8 | apache tomcat Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also | 1.6% | — |
| CVE-2023-35622 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 1.6% | — |
| CVE-2023-33934 | CRIT 9.1 | apache traffic_server Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1. | 1.6% | — |
| CVE-2021-34701 | MED 4.3 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unifie | 1.6% | — |
| CVE-2020-3181 | MED 6.5 | cisco email_security_appliance A vulnerability in the malware detection functionality in Cisco Advanced Malware Protection (AMP) in Cisco AsyncOS Software for Cisco Email Security Appliances (ESAs) could allow an unauthenticated remote attacker to exhaust resources on an affected device. Th | 1.6% | — |
| CVE-2020-3165 | HIGH 8.2 | cisco nx-os A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication in Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass MD5 authentication and establish a BGP connection with the device. Th | 1.6% | — |