57.061 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.061 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-3410 | MED 4.3 | cisco adaptive_security_appliance_software The syslog-management subsystem in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain an administrator password by waiting for an administrator to copy a file, and then (1) sniffing the network for a syslog message or (2) readin | 1.5% | — |
| CVE-2011-3283 | MED 5.0 | cisco carrier_routing_system Cisco Carrier Routing System 3.9.1 allows remote attackers to cause a denial of service (Metro subsystem crash) via a fragmented GRE packet, aka Bug ID CSCts14887. | 1.5% | — |
| CVE-2011-1877 | HIGH 7.2 | microsoft windows_7 Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverag | 1.5% | — |
| CVE-2024-21427 | HIGH 7.5 | microsoft windows_server_2012 Windows Kerberos Security Feature Bypass Vulnerability | 1.5% | — |
| CVE-2022-27806 | HIGH 8.7 | f5 big-ip_access_policy_manager On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker assigned the Administrat | 1.5% | — |
| CVE-2018-13095 | MED 5.5 | linux linux_kernel An issue was discovered in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.17.3. A denial of service (memory corruption and BUG) can occur for a corrupted xfs image upon encountering an inode that is in extent format, but has more extents than fit | 1.5% | — |
| CVE-2017-7052 | HIGH 8.8 | apple icloud An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the | 1.5% | — |
| CVE-2015-4278 | MED 4.3 | cisco email_security_appliance_firmware Cisco Email Security Appliance (ESA) devices with software 8.5.6-106 and 9.5.0-201 allow remote attackers to cause a denial of service (per-domain e-mail reception outage) by placing malformed DMARC policy data in DNS TXT records for a domain, aka Bug ID CSCuv | 1.5% | — |
| CVE-2004-0893 | HIGH 7.2 | microsoft windows_2000 The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Wind | 1.5% | — |
| CVE-2012-1361 | MED 4.3 | cisco ios Cisco IOS 15.1 and 15.2, when the Multicast Music-on-Hold (MMoH) feature of Cisco Unified Communications Manager (CUCM) is enabled, allows remote attackers to obtain sensitive crosstalk information by listening during a PSTN call, aka Bug ID CSCtx77750. | 1.5% | — |
| CVE-2008-4036 | HIGH 8.4 | microsoft windows_server_2003 Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, related to | 1.5% | — |
| CVE-2026-55944 | CRIT 9.8 | microsoft dynamics_nav Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. | 1.5% | — |
| CVE-2023-24866 | MED 6.5 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1.5% | — |
| CVE-2023-24865 | MED 6.5 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1.5% | — |
| CVE-2016-8464 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged proc | 1.5% | — |
| CVE-2009-1559 | HIGH 7.8 | cisco wvc54gca Absolute path traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R24 and possibly 1.00R22 allows remote attackers to read arbitrary files via an absolute pathname in the this_file parameter. NOTE: tra | 1.5% | — |
| CVE-2004-0208 | HIGH 7.2 | microsoft windows_2000 The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is | 1.5% | — |
| CVE-2026-55956 | MED 6.5 | apache tomcat Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22 | 1.5% | — |
| CVE-2023-35005 | MED 6.5 | apache airflow In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerability is mitigated by the fact configuration is not shown in the UI by default (only if `[webserver] expose_config` is set to `non-sensitive- | 1.5% | — |
| CVE-2023-28260 | HIGH 7.8 | microsoft .net .NET DLL Hijacking Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2021-40117 | HIGH 8.6 | cisco adaptive_security_appliance A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device | 1.5% | — |
| CVE-2020-0863 | MED 5.5 | microsoft windows_10 An information vulnerability exists when Windows Connected User Experiences and Telemetry Service improperly discloses file information, aka 'Connected User Experiences and Telemetry Service Information Disclosure Vulnerability'. | 1.5% | — |
| CVE-2020-6799 | HIGH 8.8 | mozilla firefox Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types. This required Firefox to be configured as the default handler for a given file type and for a file downloaded to be opened in a thi | 1.5% | — |
| CVE-2017-7106 | MED 6.5 | apple icloud An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar. | 1.5% | — |
| CVE-2014-7998 | HIGH 7.1 | cisco ios Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to cause a denial of service via a malformed EAP packet, aka Bug ID CSCul15509. | 1.5% | — |