57.139 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.139 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-16889 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows KernelStream improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit | 1.4% | — |
| CVE-2019-6656 | HIGH 7.5 | f5 big-ip_access_policy_manager BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerable versions of the client are bundled with BIG-IP APM versions 15.0.0-15.0.1, 14,1.0-14.1.0.6, 14.0.0-14.0.0.4, 13.0.0-13.1.1.5, 12.1.0-12.1. | 1.4% | — |
| CVE-2018-11774 | HIGH 7.2 | apache virtual_computing_lab Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in SQL statements. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin | 1.4% | — |
| CVE-2018-11772 | HIGH 7.2 | apache virtual_computing_lab Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privilege tree. The cookie data is then used in an SQL statement. This allows for an SQL injection attack. Access to th | 1.4% | — |
| CVE-2017-5043 | HIGH 8.8 | debian debian_linux Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension. | 1.4% | — |
| CVE-2013-6938 | MED 5.0 | citrix netscaler_application_delivery_controller_firmware Unspecified vulnerability in the Service VM in Citrix NetScaler SDX 9.3 before 9.3-64.4 and 10.0 before 10.0-77.5 and Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows attackers to cause a den | 1.4% | — |
| CVE-2026-45585 | MED 6.8 | microsoft windows_11_24h2 Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE | 1.4% | — |
| CVE-2024-43517 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ActiveX Data Objects Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-37971 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.4% | — |
| CVE-2024-37969 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.4% | — |
| CVE-2023-31066 | CRIT 9.1 | apache inlong Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources! Users are a | 1.4% | — |
| CVE-2022-22979 | HIGH 7.5 | vmware spring_cloud_function In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Function Catalog component of the framework. | 1.4% | — |
| CVE-2021-1590 | MED 5.3 | cisco nx-os A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a login process to unexpectedly restart, causing a denial of service (DoS) condition. This vulnerabili | 1.4% | — |
| CVE-2018-0225 | CRIT 9.8 | cisco appdynamics_app_iq The Enterprise Console in Cisco AppDynamics App iQ Platform before 4.4.3.10598 (HF4) allows SQL injection, aka the Security Advisory 2089 issue. | 1.4% | — |
| CVE-2016-1459 | MED 5.3 | cisco ios Cisco IOS 12.4 and 15.0 through 15.5 and IOS XE 3.13 through 3.17 allow remote authenticated users to cause a denial of service (device reload) via crafted attributes in a BGP message, aka Bug ID CSCuz21061. | 1.4% | — |
| CVE-2015-0750 | MED 6.5 | cisco hosted_collaboration_solution The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier allows remote authenticated users to execute arbitrary commands via crafted input to unspecified fields, aka Bug ID CSCut02786. | 1.4% | — |
| CVE-2009-1164 | HIGH 7.8 | cisco catalyst_3750g The administrative web interface on the Cisco Wireless LAN Controller (WLC) platform 4.2 before 4.2.205.0 and 5.x before 5.2.178.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 4200 Series, and 4400 Series Wireless Services Modules (WiS | 1.4% | — |
| CVE-2006-3732 | MED 5.0 | cisco cs-mars Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1 ships with an Oracle database that contains several default accounts and passwords, which allows attackers to obtain sensitive information. | 1.4% | — |
| CVE-2025-30378 | HIGH 7.0 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | 1.4% | — |
| CVE-2024-30052 | MED 4.7 | microsoft visual_studio_2019 Visual Studio Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-36758 | HIGH 7.8 | microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2023-30448 | MED 5.9 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253437. | 1.4% | — |
| CVE-2020-26966 | MED 6.5 | mozilla firefox Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: This issue only affected Windows operating systems. Other opera | 1.4% | — |
| CVE-2015-0571 | HIGH 7.8 | linux linux_kernel The WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify authorization for private SET IOCTL calls, which allows attackers to gain privi | 1.4% | — |
| CVE-2015-0583 | MED 5.0 | cisco webex_meeting_center Cisco WebEx Meeting Center does not properly restrict the content of URLs, which allows remote attackers to obtain sensitive information via vectors related to file: URIs, aka Bug ID CSCus18281. | 1.4% | — |