IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2023-28271 MED 5.5 microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability 1.2% —
CVE-2022-23269 MED 5.4 microsoft dynamics_gp Microsoft Dynamics GP Spoofing Vulnerability 1.2% —
CVE-2021-40122 MED 5.9 cisco meeting_server A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper handling of large series of message requests. An at 1.2% —
CVE-2020-27121 MED 4.3 cisco unified_communications_manager_im_and_presence_service A vulnerability in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) Software could allow an authenticated, remote attacker to cause the Cisco XCP Authentication Service on an affected device to restart, resulting in a denial 1.2% —
CVE-2020-24003 LOW 3.3 microsoft skype Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Skype Cli 1.2% —
CVE-2015-5156 MED 6.1 linux linux_kernel The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via 1.2% —
CVE-2015-4266 MED 4.3 cisco identity_services_engine_software The web interface in Cisco Identity Services Engine (ISE) 1.1(4.1), 1.3(106.146), and 1.3(120.135) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a 1.2% —
CVE-2012-2852 MED 6.8 google chrome The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly handle object linkage, which allows remote attackers to cause a denial of service (use-after-free) or possi 1.2% —
CVE-2011-1874 HIGH 7.8 microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain 1.2% —
CVE-2023-21539 HIGH 7.5 microsoft windows_10_20h2 Windows Authentication Remote Code Execution Vulnerability 1.2% —
CVE-2018-0254 MED 5.3 cisco secure_firewall_threat_defense A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. 1.2% —
CVE-2018-0244 MED 5.8 cisco secure_firewall_threat_defense A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy to drop the Server Message Block (SMB) protocol if a malware file is detected. The vulnerabilit 1.2% —
CVE-2018-0243 MED 5.8 cisco secure_firewall_threat_defense A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy that is intended to drop the Server Message Block Version 2 (SMB2) and SMB Version 3 (SMB3) pro 1.2% —
CVE-2018-0138 MED 5.3 cisco secure_firewall_threat_defense A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass file policies that are configured to block files transmitted to an affected device via the BitTorrent protocol. The vulnerabili 1.2% —
CVE-2017-2325 MED 6.5 juniper northstar_controller A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to cause a buffer overflow leading to a denial of service. 1.2% —
CVE-2017-12299 MED 5.3 cisco firepower_extensible_operating_system A vulnerability exists in the process of creating default IP blocks during device initialization for Cisco ASA Next-Generation Firewall Services that could allow an unauthenticated, remote attacker to send traffic to the local IP address of the device, bypassi 1.2% —
CVE-2024-28899 HIGH 8.8 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.2% —
CVE-2023-31065 CRIT 9.1 apache inlong Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.  An old session can be used by an attacker even after the user has been deleted or the password has been cha 1.2% —
CVE-2023-28158 MED 6.5 apache archiva Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user. 1.2% —
CVE-2022-46907 MED 6.1 apache jspwiki A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users 1.2% —
CVE-2022-41066 MED 4.4 microsoft dynamics_365_business_central_2019 Microsoft Dynamics Business Central Information Disclosure Vulnerability 1.2% —
CVE-2021-26642 HIGH 8.8 xpressengine xpressengine When uploading an image file to a bulletin board developed with XpressEngine, a vulnerability in which an arbitrary file can be uploaded due to insufficient verification of the file. A remote attacker can use this vulnerability to execute arbitrary code on the 1.2% —
CVE-2021-1465 MED 4.3 cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a directory traversal attack and obtain read access to sensitive files on an affected system. The vulnerability is 1.2% —
CVE-2017-6766 HIGH 7.5 cisco firesight_system_software A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection feature of Cisco Firepower System Software 5.4.0, 5.4.1, 6.0.0, 6.1.0, 6.2.0, 6.2.1, and 6.2.2 could allow an unauthenticated, remote attacker to bypass the SSL policy for decrypting a 1.2% —
CVE-2017-5986 MED 5.5 linux linux_kernel Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithreaded application that peels off an association in a certain 1.2% —