57.080 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.080 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-3130 | HIGH 7.5 | fortinet fortios An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting FortiOS IKE VendorID packets. | 1.4% | — |
| CVE-2017-6673 | MED 6.5 | cisco secure_firewall_management_center A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker to obtain user information. An attacker could use this information to perform reconnaissance. More Information: CSCvc10894. Known Affected Releases: 6.1.0.2 6.2. | 1.4% | — |
| CVE-2017-0312 | HIGH 7.8 | nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscapeID 0x100008b where user provided input is used as the limit for a loop may lead to denial of service or potential escalat | 1.4% | — |
| CVE-2019-17652 | MED 6.5 | fortinet forticlient A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to cause FortiClient processes running under root priviledge crashes via sending specially crafted "StartAvCustomScan" type IPC client requests t | 1.4% | — |
| CVE-2019-6634 | MED 6.5 | f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, a high volume of malformed analytics report requests leads to instability in restjavad process. This causes issues with both iControl REST and some portions of TMUI. The attack req | 1.4% | — |
| CVE-2016-6394 | CRIT 9.1 | cisco firesight_system_software Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503. | 1.4% | — |
| CVE-2011-1101 | MED 6.8 | citrix licensing_administration_console Multiple unspecified vulnerabilities in a third-party component of the Citrix Licensing Administration Console 11.6, formerly License Management Console, allow remote attackers to (1) access unauthorized "license administration functionality" or (2) cause a de | 1.4% | — |
| CVE-2023-30771 | CRIT 9.8 | apache iotdb_web_workbench Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database. This problem is fi | 1.4% | — |
| CVE-2020-27132 | CRIT 9.9 | cisco jabber Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive informati | 1.4% | — |
| CVE-2014-9322 | HIGH 7.8 | canonical ubuntu_linux arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Bas | 1.4% | — |
| CVE-2024-51941 | HIGH 8.8 | apache ambari A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability occurs when processing alert definitions, where malicious input can be injected i | 1.4% | — |
| CVE-2024-24746 | HIGH 7.5 | apache nimble Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: throu | 1.4% | — |
| CVE-2023-26512 | CRIT 9.8 | apache eventmesh-connector-rabbitmq CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq messages. | 1.4% | — |
| CVE-2022-26112 | CRIT 9.8 | apache pinot In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pin | 1.4% | — |
| CVE-2013-6367 | MED 5.7 | linux linux_kernel The apic_get_tmcct function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via crafted modifications of the TMICT value. | 1.4% | — |
| CVE-2011-1239 | HIGH 7.2 | microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain | 1.4% | — |
| CVE-2009-0320 | MED 4.0 | microsoft windows_server_2003 Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estim | 1.4% | — |
| CVE-2002-0969 | HIGH 7.8 | oracle mysql Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Con | 1.4% | — |
| CVE-2023-22849 | MED 6.1 | apache sling_cms An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in multi | 1.4% | — |
| CVE-2021-41025 | HIGH 7.3 | fortinet fortiweb Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurrent execution using shared resource with i | 1.4% | — |
| CVE-2019-1460 | MED 4.6 | microsoft outlook A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing Vulnerability'. | 1.4% | — |
| CVE-2018-5548 | MED 6.1 | f5 big-ip_access_policy_manager On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using different blocks of cipher | 1.4% | — |
| CVE-2013-6974 | MED 4.3 | cisco secure_access_control_system Cross-site scripting (XSS) vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud89431. | 1.4% | — |
| CVE-2022-20685 | HIGH 7.5 | cisco cyber_vision A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer overflow while processing Modb | 1.4% | — |
| CVE-2024-37341 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Elevation of Privilege Vulnerability | 1.4% | — |