IT
57.298 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync

CVE Tracker

57.298 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-38427 CRIT 9.8 linux linux_kernel An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts. 1.2%
CVE-2020-16897 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p 1.2%
CVE-2013-2914 MED 6.8 google chrome Use-after-free vulnerability in the color-chooser dialog in Google Chrome before 30.0.1599.66 on Windows allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to color_chooser_dialog.cc and color_cho 1.2%
CVE-2009-2908 MED 4.9 linux linux_kernel The d_delete function in fs/ecryptfs/inode.c in eCryptfs in the Linux kernel 2.6.31 allows local users to cause a denial of service (kernel OOPS) and possibly execute arbitrary code via unspecified vectors that cause a "negative dentry" and trigger a NULL poin 1.2%
CVE-2003-1305 MED 5.0 Microsoft Internet Explorer allows remote attackers to cause a denial of service (resource consumption) via a Javascript src attribute that recursively loads the current web page. 1.2%
CVE-2023-20040 MED 5.5 cisco network_services_orchestrator A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial of service (DoS) on an affected system that is running as the root user. To exploit this vulnerability, the atta 1.2%
CVE-2022-34704 MED 4.7 microsoft windows_10 Windows Defender Credential Guard Information Disclosure Vulnerability 1.2%
CVE-2022-20889 MED 4.7 cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1.2%
CVE-2020-4324 MED 4.3 ibm security_secret_server IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improper input validation. IBM X-Force ID: 177515. 1.2%
CVE-2019-6600 MED 6.1 f5 big-ip_access_policy_manager In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when remote authentication is enabled for administrative users and all external users are granted the "guest" role, unsanitized values can be reflected to the clien 1.2%
CVE-2018-0820 HIGH 7.8 microsoft windows_10 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulne 1.2%
CVE-2018-0742 HIGH 7.8 microsoft windows_10 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulne 1.2%
CVE-2017-6764 MED 5.4 cisco adaptive_security_appliance_software A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.5(1) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affe 1.2%
CVE-2017-6661 MED 6.1 cisco content_security_management_appliance A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of 1.2%
CVE-2009-0438 MED 5.0 ibm websphere_application_server IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information from JSP pages via a crafted request. NOTE: this is probably a duplicate of CVE-2008-5412. 1.2%
CVE-2024-47554 MED 4.3 apache commons_io Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 befor 1.2%
CVE-2024-28925 HIGH 8.0 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.2%
CVE-2012-0055 HIGH 7.8 canonical ubuntu_linux OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions. 1.2%
CVE-2024-31141 MED 6.5 apache kafka Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in order to manipulate these 1.2%
CVE-2024-21448 MED 5.0 microsoft teams Microsoft Teams for Android Information Disclosure Vulnerability 1.2%
CVE-2023-36009 MED 5.5 microsoft 365_apps Microsoft Word Information Disclosure Vulnerability 1.2%
CVE-2023-32056 HIGH 7.8 microsoft windows_10_1809 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability 1.2%
CVE-2021-3772 MED 6.5 debian debian_linux A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses. 1.2%
CVE-2021-26418 MED 4.6 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 1.2%
CVE-2020-1679 HIGH 7.5 juniper junos On Juniper Networks PTX and QFX Series devices with packet sampling configured using tunnel-observation mpls-over-udp, sampling of a malformed packet can cause the Kernel Routing Table (KRT) queue to become stuck. KRT is the module within the Routing Process D 1.2%