57.298 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.298 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-38427 | CRIT 9.8 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts. | 1.2% | — |
| CVE-2020-16897 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p | 1.2% | — |
| CVE-2013-2914 | MED 6.8 | google chrome Use-after-free vulnerability in the color-chooser dialog in Google Chrome before 30.0.1599.66 on Windows allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to color_chooser_dialog.cc and color_cho | 1.2% | — |
| CVE-2009-2908 | MED 4.9 | linux linux_kernel The d_delete function in fs/ecryptfs/inode.c in eCryptfs in the Linux kernel 2.6.31 allows local users to cause a denial of service (kernel OOPS) and possibly execute arbitrary code via unspecified vectors that cause a "negative dentry" and trigger a NULL poin | 1.2% | — |
| CVE-2003-1305 | MED 5.0 | Microsoft Internet Explorer allows remote attackers to cause a denial of service (resource consumption) via a Javascript src attribute that recursively loads the current web page. | 1.2% | — |
| CVE-2023-20040 | MED 5.5 | cisco network_services_orchestrator A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial of service (DoS) on an affected system that is running as the root user. To exploit this vulnerability, the atta | 1.2% | — |
| CVE-2022-34704 | MED 4.7 | microsoft windows_10 Windows Defender Credential Guard Information Disclosure Vulnerability | 1.2% | — |
| CVE-2022-20889 | MED 4.7 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1.2% | — |
| CVE-2020-4324 | MED 4.3 | ibm security_secret_server IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improper input validation. IBM X-Force ID: 177515. | 1.2% | — |
| CVE-2019-6600 | MED 6.1 | f5 big-ip_access_policy_manager In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when remote authentication is enabled for administrative users and all external users are granted the "guest" role, unsanitized values can be reflected to the clien | 1.2% | — |
| CVE-2018-0820 | HIGH 7.8 | microsoft windows_10 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulne | 1.2% | — |
| CVE-2018-0742 | HIGH 7.8 | microsoft windows_10 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulne | 1.2% | — |
| CVE-2017-6764 | MED 5.4 | cisco adaptive_security_appliance_software A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.5(1) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affe | 1.2% | — |
| CVE-2017-6661 | MED 6.1 | cisco content_security_management_appliance A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of | 1.2% | — |
| CVE-2009-0438 | MED 5.0 | ibm websphere_application_server IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information from JSP pages via a crafted request. NOTE: this is probably a duplicate of CVE-2008-5412. | 1.2% | — |
| CVE-2024-47554 | MED 4.3 | apache commons_io Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 befor | 1.2% | — |
| CVE-2024-28925 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2012-0055 | HIGH 7.8 | canonical ubuntu_linux OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions. | 1.2% | — |
| CVE-2024-31141 | MED 6.5 | apache kafka Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in order to manipulate these | 1.2% | — |
| CVE-2024-21448 | MED 5.0 | microsoft teams Microsoft Teams for Android Information Disclosure Vulnerability | 1.2% | — |
| CVE-2023-36009 | MED 5.5 | microsoft 365_apps Microsoft Word Information Disclosure Vulnerability | 1.2% | — |
| CVE-2023-32056 | HIGH 7.8 | microsoft windows_10_1809 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2021-3772 | MED 6.5 | debian debian_linux A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses. | 1.2% | — |
| CVE-2021-26418 | MED 4.6 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1.2% | — |
| CVE-2020-1679 | HIGH 7.5 | juniper junos On Juniper Networks PTX and QFX Series devices with packet sampling configured using tunnel-observation mpls-over-udp, sampling of a malformed packet can cause the Kernel Routing Table (KRT) queue to become stuck. KRT is the module within the Routing Process D | 1.2% | — |