IT
57.217 CVE tracked
779 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.217 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-28672 CRIT 9.8 apache ranger Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8. 1.3%
CVE-2024-31868 MED 6.1 apache zeppelin Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 1.3%
CVE-2022-20679 MED 6.8 cisco ios_xe A vulnerability in the IPSec decryption routine of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to buffer exhaustion tha 1.3%
CVE-2021-0206 HIGH 7.5 juniper junos A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to send a specific packet causing the packet forwarding engine (PFE) to crash and restart, resulting in a Denial of Service (DoS). By continuously sending these specific p 1.3%
CVE-2020-35963 HIGH 7.8 treasuredata fluent_bit flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calculation of the maximum gzip data-size expansion. 1.3%
CVE-2019-9801 MED 5.3 mozilla firefox Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL 1.3%
CVE-2018-8028 HIGH 8.8 apache sentry An authenticated user can execute ALTER TABLE EXCHANGE PARTITIONS without being authorized by Apache Sentry before 2.0.1. This can allow an attacker unauthorized access to the partitioned data of a Sentry protected table and can allow an attacker to remove dat 1.3%
CVE-2008-5882 HIGH 7.5 avaya broadcast_server SQL injection vulnerability in login.asp in Citrix Application Gateway - Broadcast Server (BCS) before 6.1, as used by Avaya AG250 - Broadcast Server before 2.0 and possibly other products, allows remote attackers to execute arbitrary SQL commands via the txtU 1.3%
CVE-2007-4018 MED 6.8 citrix access_gateway Citrix Access Gateway Advanced Edition before firmware 4.5.5 allows attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors. 1.3%
CVE-2021-43030 LOW 3.3 adobe premiere_rush Adobe Premiere Rush versions 1.5.16 (and earlier) allows access to an uninitialized pointer vulnerability that allows remote attackers to disclose arbitrary data on affected installations. User interaction is required to exploit this vulnerability in that the 1.3%
CVE-2020-3955 CRIT 9.3 vmware esxi ESXi 6.5 without patch ESXi650-201912104-SG and ESXi 6.7 without patch ESXi670-202004103-SG do not properly neutralize script-related HTML when viewing virtual machines attributes. VMware has evaluated the severity of this issue to be in the Important severity 1.3%
CVE-2019-0075 HIGH 7.5 juniper junos A vulnerability in the srxpfe process on Protocol Independent Multicast (PIM) enabled SRX series devices may lead to crash of the srxpfe process and an FPC reboot while processing (PIM) messages. Sustained receipt of these packets may lead to an extended denia 1.3%
CVE-2019-0068 MED 6.5 juniper junos The SRX flowd process, responsible for packet forwarding, may crash and restart when processing specific multicast packets. By continuously sending the specific multicast packets, an attacker can repeatedly crash the flowd process causing a sustained Denial of 1.3%
CVE-2019-6629 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts 1.3%
CVE-2017-6668 MED 4.9 cisco unified_communications_domain_manager Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc 1.3%
CVE-2012-4143 MED 6.8 opera opera_browser Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, allows user-assisted remote attackers to trick users into downloading and executing arbitrary files via a small window for the download dialog, a different vulnerabilit 1.3%
CVE-2011-4500 HIGH 7.5 cisco linksys_wrt54gx_router_firmware The UPnP IGD implementation on the Cisco Linksys WRT54GX with firmware 2.00.05, when UPnP is enabled, configures the SOAP server to listen on the WAN port, which allows remote attackers to administer the firewall via SOAP requests. 1.3%
CVE-2011-4499 HIGH 7.5 cisco linksys_wrt54g_router_firmware The UPnP IGD implementation in the Broadcom UPnP stack on the Cisco Linksys WRT54G with firmware before 4.30.5, WRT54GS v1 through v3 with firmware before 4.71.1, and WRT54GS v4 with firmware before 1.06.1 allows remote attackers to establish arbitrary port ma 1.3%
CVE-2007-6052 HIGH 7.8 ibm db2_universal_database IBM DB2 UDB 9.1 before Fixpak 4 does not properly perform vector aggregation, which might allow attackers to cause a denial of service (divide-by-zero error and DBMS crash), related to an "overflow." NOTE: the vendor description of this issue is too vague to b 1.3%
CVE-2024-1654 HIGH 7.2 papercut papercut_mf This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to explo 1.3%
CVE-2022-45802 CRIT 9.8 apache streampark Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to A 1.3%
CVE-2020-17056 MED 5.5 microsoft windows_10 Windows Network File System Information Disclosure Vulnerability 1.3%
CVE-2020-17013 MED 5.5 microsoft windows_10 Win32k Information Disclosure Vulnerability 1.3%
CVE-2020-17004 MED 5.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 1.3%
CVE-2020-17000 MED 5.5 microsoft windows_10 Remote Desktop Protocol Client Information Disclosure Vulnerability 1.3%