58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-6424 | MED 6.5 | cisco adaptive_security_appliance_software The DHCP Relay implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4.7.29 and 9.1.7.4 allows remote attackers to cause a denial of service (interface wedge) via a crafted rate of DHCP packet transmission, aka Bug ID CSCuy66942. | 1.1% | — |
| CVE-2011-2723 | MED 5.7 | linux linux_kernel The skb_gro_header_slow function in include/linux/netdevice.h in the Linux kernel before 2.6.39.4, when Generic Receive Offload (GRO) is enabled, resets certain fields in incorrect situations, which allows remote attackers to cause a denial of service (system | 1.1% | — |
| CVE-2026-21250 | HIGH 7.8 | microsoft windows_11_24h2 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | 1.1% | — |
| CVE-2025-62456 | HIGH 8.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2022-20738 | MED 5.8 | cisco umbrella_secure_web_gateway A vulnerability in the Cisco Umbrella Secure Web Gateway service could allow an unauthenticated, remote attacker to bypass the file inspection feature. This vulnerability is due to insufficient restrictions in the file inspection feature. An attacker could exp | 1.1% | — |
| CVE-2021-29736 | HIGH 8.8 | ibm websphere_application_server IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300. | 1.1% | — |
| CVE-2018-16969 | MED 4.3 | citrix sharefile_storagezones_controller Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message. | 1.1% | — |
| CVE-2016-6412 | MED 6.5 | cisco ios The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via crafted HTTP headers, aka Bug ID CSCuz84773. | 1.1% | — |
| CVE-2015-4297 | MED 5.8 | cisco webex_node_for_mcs Open redirect vulnerability in Cisco WebEx Node for Media Convergence Server (MCS) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted HTTP request parameters, aka Bug ID CSCuv32136. | 1.1% | — |
| CVE-2013-1661 | MED 4.3 | vmware esx VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to cause a denial of service (unhandled exception and application crash) by modifying the client-server | 1.1% | — |
| CVE-2009-3087 | MED 5.0 | ibm lotus_domino Unspecified vulnerability in nserver.exe in the server in IBM Lotus Domino 8.0 on Windows Server 2003 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8. | 1.1% | — |
| CVE-2006-7034 | HIGH 7.5 | super_link_exchange_script super_link_exchange_script SQL injection vulnerability in directory.php in Super Link Exchange Script 1.0 might allow remote attackers to execute arbitrary SQL queries via the cat parameter. | 1.1% | — |
| CVE-2024-49132 | HIGH 8.1 | microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-49123 | HIGH 8.1 | microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-49065 | MED 5.5 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-23537 | HIGH 8.4 | apache fineract Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.9.0, which fixes the issue. | 1.1% | — |
| CVE-2023-47701 | MED 6.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 266166. | 1.1% | — |
| CVE-2023-1192 | MED 6.5 | linux linux_kernel A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses i | 1.1% | — |
| CVE-2018-0831 | HIGH 7.8 | microsoft windows_10 The Windows kernel in Windows 10 versions 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Kernel Elevation of Privilege Vulnerabilit | 1.1% | — |
| CVE-2017-7661 | HIGH 8.8 | apache cxf_fediz Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3, Jetty 8 and Jetty 9 plugins in Apache CXF Fediz prio | 1.1% | — |
| CVE-2017-5573 | MED 4.9 | citrix xenserver An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can cancel tasks of other administrators. | 1.1% | — |
| CVE-2017-5572 | MED 6.5 | citrix xenserver An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can corrupt the host database. | 1.1% | — |
| CVE-2016-6395 | MED 5.4 | cisco firesight_system_software Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, | 1.1% | — |
| CVE-2023-4593 | MED 6.5 | seattlelab slmail Path traversal vulnerability whose exploitation could allow an authenticated remote user to bypass SecurityManager's intended restrictions and list a parent directory via any filename, such as a multiple ..%2F value affecting the 'dodoc' parameter in the /Mail | 1.1% | — |
| CVE-2023-35701 | MED 6.6 | apache hive Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and it can potentially lead to arbitrary code execution on the machine/endpoint that the JDBC driver (client) is r | 1.1% | — |