57.065 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.065 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-20573 | MED 6.5 | ibm security_identity_manager_adapter IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow the and cause the server to crash. IBM X-Force ID: 199249. | 1.5% | — |
| CVE-2021-20572 | MED 6.5 | ibm security_identity_manager_adapter IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow the and cause the server to crash. IBM X-Force ID: 199247. | 1.5% | — |
| CVE-2020-17145 | MED 5.4 | microsoft azure_devops_server Azure DevOps Server and Team Foundation Services Spoofing Vulnerability | 1.5% | — |
| CVE-2020-0642 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0624. | 1.5% | — |
| CVE-2013-4486 | CRIT 9.8 | redhat zanata Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging | 1.5% | — |
| CVE-2015-0598 | MED 6.8 | cisco ios The RADIUS implementation in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (device reload) via crafted IPv6 Attributes in Access-Accept packets, aka Bug IDs CSCur84322 and CSCur27693. | 1.5% | — |
| CVE-2014-3269 | MED 6.8 | cisco ios_xe The SNMP module in Cisco IOS XE 3.5E allows remote authenticated users to cause a denial of service (device reload) by polling frequently, aka Bug ID CSCug65204. | 1.5% | — |
| CVE-2013-6686 | MED 6.8 | cisco ios The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug IDs CSCuh97409 and CSCud90568. | 1.5% | — |
| CVE-2025-21283 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2021-47295 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: sched: fix memory leak in tcindex_partial_destroy_work Syzbot reported memory leak in tcindex_set_parms(). The problem was in non-freed perfect hash in tcindex_partial_destroy_work(). | 1.5% | — |
| CVE-2023-47037 | MED 4.3 | apache airflow We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then. Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values whe | 1.5% | — |
| CVE-2023-21745 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 1.5% | — |
| CVE-2022-30203 | HIGH 7.4 | microsoft windows_10 Windows Boot Manager Security Feature Bypass Vulnerability | 1.5% | — |
| CVE-2021-41972 | MED 6.5 | apache superset Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way. | 1.5% | — |
| CVE-2020-5884 | CRIT 9.1 | f5 big-ip_access_policy_manager On versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.4, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the default deployment mode for BIG-IP high availability (HA) pair mirroring is insecure. This is a control plane issue that is exposed only on the network use | 1.5% | — |
| CVE-2015-8964 | MED 5.5 | linux linux_kernel The tty_set_termios_ldisc function in drivers/tty/tty_ldisc.c in the Linux kernel before 4.5 allows local users to obtain sensitive information from kernel memory by reading a tty data structure. | 1.5% | — |
| CVE-2016-0197 | HIGH 7.8 | microsoft windows_10 dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows | 1.5% | — |
| CVE-2015-0671 | MED 5.0 | cisco videoscape_delivery_system_for_internet_streamer The DNS implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.2(1) allows remote attackers to cause a denial of service (CPU consumption and network-resource consumption) via crafted packets, aka Bug ID CSCun15911. | 1.5% | — |
| CVE-2014-3166 | MED 4.3 | debian debian_linux The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitiv | 1.5% | — |
| CVE-2013-5536 | MED 5.0 | cisco secure_access_control_system Cisco Secure Access Control System (ACS) does not properly implement an incoming-packet firewall rule, which allows remote attackers to cause a denial of service (process crash) via a flood of crafted packets, aka Bug ID CSCui51521. | 1.5% | — |
| CVE-2013-1190 | MED 5.0 | cisco unified_computing_system The C-Series Rack Server component 1.4 in Cisco Unified Computing System (UCS) does not properly restrict inbound access to ports, which allows remote attackers to cause a denial of service (Integrated Management Controller reboot or hang) via crafted packets, | 1.5% | — |
| CVE-2012-3913 | MED 5.0 | cisco vc240_network_bullet_camera The Cisco VC220 and VC240 cameras allow remote attackers to cause a denial of service (WebUI outage) via crafted packets, aka Bug IDs CSCtf73188, CSCtf88059, CSCtf87951, CSCtf87908, and CSCtf88019. | 1.5% | — |
| CVE-2013-1138 | MED 5.0 | cisco adaptive_security_appliance The NAT process on Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (connections-table memory consumption) via crafted packets, aka Bug ID CSCue46386. | 1.5% | — |
| CVE-2003-1372 | MED 4.3 | myphpnuke myphpnuke Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the (1) ratenum or (2) query parameters. | 1.5% | — |
| CVE-2024-43533 | HIGH 8.8 | microsoft windows_11_21h2 Remote Desktop Client Remote Code Execution Vulnerability | 1.5% | — |