57.136 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.136 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-26421 | MED 6.5 | microsoft lync_server Skype for Business and Lync Spoofing Vulnerability | 1.4% | — |
| CVE-2017-8746 | MED 5.3 | microsoft windows_10 Windows Device Guard in Windows 10 1607, 1703, and Windows Server 2016 allows A security feature bypass vulnerability due to how PowerShell exposes functions and processes user supplied code, aka "Device Guard Security Feature Bypass Vulnerability". | 1.4% | — |
| CVE-2017-8290 | HIGH 7.5 | teamspeak teamspeak_client A potential Buffer Overflow Vulnerability (from a BB Code handling issue) has been identified in TeamSpeak Server version 3.0.13.6 (08/11/2016 09:48:33), it enables the users to Crash any WINDOWS Client that clicked into a Vulnerable Channel of a TeamSpeak Ser | 1.4% | — |
| CVE-2016-6474 | HIGH 7.3 | cisco ios A vulnerability in the implementation of X.509 Version 3 for SSH authentication functionality in Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on an affected system. More Information: CSCuv89417. Known A | 1.4% | — |
| CVE-2009-2976 | HIGH 7.8 | cisco aironet_ap1100 Cisco Aironet Lightweight Access Point (AP) devices send the contents of certain multicast data frames in cleartext, which allows remote attackers to discover Wireless LAN Controller MAC addresses and IP addresses, and AP configuration details, by sniffing the | 1.4% | — |
| CVE-2023-22832 | HIGH 7.5 | apache nifi The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type | 1.4% | — |
| CVE-2021-22125 | MED 6.3 | fortinet fortisandbox An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's shell via altering the content of its configuration file. | 1.4% | — |
| CVE-2021-1349 | MED 6.5 | cisco sd-wan_vmanage A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on an affected system. The vulnerability is due to insufficient input valida | 1.4% | — |
| CVE-2019-9963 | HIGH 7.8 | xnview xnview_mp XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlFreeHeap. | 1.4% | — |
| CVE-2017-6136 | MED 5.9 | f5 big-ip_access_policy_manager In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0 and 12.0.0 - 12.1.2, undisclosed traffic patterns sent to BIG-IP virtual servers, with the TCP Fast Open and Tail Loss Probe options enabled in | 1.4% | — |
| CVE-2017-8890 | HIGH 7.8 | debian debian_linux The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call. | 1.4% | — |
| CVE-1999-1358 | MED 4.6 | microsoft windows_2000 When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the po | 1.4% | — |
| CVE-2023-24997 | CRIT 9.8 | apache inlong Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inl | 1.4% | — |
| CVE-2021-37594 | CRIT 9.8 | freerdp freerdp In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_SIZE File Contents Request PDU. | 1.4% | — |
| CVE-2021-1144 | HIGH 8.8 | cisco connected_mobile_experiences A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an affected system. The vulnerability is due to incorrect handling of authorization | 1.4% | — |
| CVE-2020-9615 | HIGH 7.0 | adobe acrobat_dc Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a race condition vulnerability. Successful exploitation could lead to security feature bypass. | 1.4% | — |
| CVE-2016-7386 | MED 5.5 | nvidia gpu_driver For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70000D4 which may lead to leaking of ke | 1.4% | — |
| CVE-2005-2451 | LOW 2.1 | cisco ios Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly execute arbitrary code via a crafted IPv6 packet. | 1.4% | — |
| CVE-2024-20655 | MED 6.6 | microsoft windows_server_2008 Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-21553 | HIGH 7.5 | microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2021-43752 | LOW 3.3 | adobe illustrator Adobe Illustrator versions 25.4.2 (and earlier) and 26.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex | 1.4% | — |
| CVE-2019-6614 | MED 6.5 | f5 big-ip_access_policy_manager On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, internal methods used to prevent arbitrary file overwrites in Appliance Mode were not fully effective. An authenticated attacker with a high privilege level may be able to bypass protections implem | 1.4% | — |
| CVE-1999-0496 | HIGH 7.2 | microsoft windows_nt A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin. | 1.4% | — |
| CVE-2015-6290 | MED 4.3 | cisco web_security_virtual_appliance Cisco Web Security Appliance (WSA) 8.0.7 allows remote HTTP servers to cause a denial of service (memory consumption from stale TCP connections) via crafted responses, aka Bug ID CSCuw10426. | 1.4% | — |
| CVE-2010-1886 | MED 6.8 | microsoft windows_2003_server Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI | 1.4% | — |