IT
57.065 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.065 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2017-8704 MED 5.3 microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows a denial of service vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Denial of Service Vulnerab 1.5%
CVE-2025-46762 HIGH 8.1 apache parquet Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code. While 1.15.1 introduced a fix to restrict untrusted packages, the default setting of trusted packages still allows malicious 1.5%
CVE-2024-23539 HIGH 8.3 apache fineract Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue. 1.5%
CVE-2021-1446 HIGH 8.6 cisco ios_xe A vulnerability in the DNS application layer gateway (ALG) functionality used by Network Address Translation (NAT) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a log 1.5%
CVE-2021-1437 HIGH 7.5 cisco aironet_access_point_software A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial F 1.5%
CVE-2020-3444 HIGH 7.5 cisco ios_xe A vulnerability in the packet filtering features of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters. The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker 1.5%
CVE-2016-0057 HIGH 7.8 microsoft office Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 does not properly sign an unspecified binary file, which allows local users to gain privileges via a Trojan horse file with a crafted signature, aka "Microsoft Office Security Feature Bypass Vulnerability 1.5%
CVE-2024-21303 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.5%
CVE-2022-26850 MED 4.3 apache nifi When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers configuration to the operating system temporary directory. On most platforms, the operating system temporary directory has global read permis 1.5%
CVE-2021-1373 HIGH 8.6 cisco ios_xe A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause 1.5%
CVE-2019-12701 MED 5.8 cisco secure_firewall_management_center A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass the file and malware inspection policies on an affected system. The vulnerability exists be 1.5%
CVE-2019-1970 MED 5.8 cisco secure_firewall_management_center A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected s 1.5%
CVE-2019-1909 MED 6.8 cisco ios_xr A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to incorr 1.5%
CVE-2017-5052 HIGH 8.8 google chrome An incorrect assumption about block structure in Blink in Google Chrome prior to 57.0.2987.133 for Mac, Windows, and Linux, and 57.0.2987.132 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page that triggers 1.5%
CVE-2016-1290 HIGH 8.1 cisco evolved_programmable_network_manager The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a 1.5%
CVE-2007-0964 MED 5.4 cisco firewall_services_module Cisco FWSM 3.x before 3.1(3.18), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a malformed HTTPS request. 1.5%
CVE-1999-0794 MED 4.6 microsoft excel Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file. 1.5%
CVE-2023-36427 HIGH 7.0 microsoft windows_10_1809 Windows Hyper-V Elevation of Privilege Vulnerability 1.5%
CVE-2019-1953 MED 6.5 cisco enterprise_nfv_infrastructure_software A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging the admin password when a user is forced t 1.5%
CVE-2018-0218 LOW 3.3 cisco secure_access_control_server_solution_engine A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system. The vulnerability is due to improp 1.5%
CVE-2017-5583 MED 6.5 paloaltonetworks pan-os The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to read arbitrary files via unspecified vectors. 1.5%
CVE-2016-3305 HIGH 7.8 microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 mishandles session objects, which allows local users to hijack sessi 1.5%
CVE-2016-1380 HIGH 7.5 cisco web_security_appliance Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (proxy-process hang) via a crafted HTTP POST request, aka Bug ID CSCuo12171. 1.5%
CVE-2023-25613 CRIT 9.8 apache kerby_ldap_backend An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3.  1.5%
CVE-2022-23770 HIGH 8.8 wisa smart_wing_cms This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remote attackers could use this vulnerability to execute malicious commands such as directory traversal. 1.5%