IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2016-6424 MED 6.5 cisco adaptive_security_appliance_software The DHCP Relay implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4.7.29 and 9.1.7.4 allows remote attackers to cause a denial of service (interface wedge) via a crafted rate of DHCP packet transmission, aka Bug ID CSCuy66942. 1.1% —
CVE-2011-2723 MED 5.7 linux linux_kernel The skb_gro_header_slow function in include/linux/netdevice.h in the Linux kernel before 2.6.39.4, when Generic Receive Offload (GRO) is enabled, resets certain fields in incorrect situations, which allows remote attackers to cause a denial of service (system 1.1% —
CVE-2026-21250 HIGH 7.8 microsoft windows_11_24h2 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 1.1% —
CVE-2025-62456 HIGH 8.8 microsoft windows_11_23h2 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. 1.1% —
CVE-2022-20738 MED 5.8 cisco umbrella_secure_web_gateway A vulnerability in the Cisco Umbrella Secure Web Gateway service could allow an unauthenticated, remote attacker to bypass the file inspection feature. This vulnerability is due to insufficient restrictions in the file inspection feature. An attacker could exp 1.1% —
CVE-2021-29736 HIGH 8.8 ibm websphere_application_server IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300. 1.1% —
CVE-2018-16969 MED 4.3 citrix sharefile_storagezones_controller Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message. 1.1% —
CVE-2016-6412 MED 6.5 cisco ios The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via crafted HTTP headers, aka Bug ID CSCuz84773. 1.1% —
CVE-2015-4297 MED 5.8 cisco webex_node_for_mcs Open redirect vulnerability in Cisco WebEx Node for Media Convergence Server (MCS) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted HTTP request parameters, aka Bug ID CSCuv32136. 1.1% —
CVE-2013-1661 MED 4.3 vmware esx VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to cause a denial of service (unhandled exception and application crash) by modifying the client-server 1.1% —
CVE-2009-3087 MED 5.0 ibm lotus_domino Unspecified vulnerability in nserver.exe in the server in IBM Lotus Domino 8.0 on Windows Server 2003 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8. 1.1% —
CVE-2006-7034 HIGH 7.5 super_link_exchange_script super_link_exchange_script SQL injection vulnerability in directory.php in Super Link Exchange Script 1.0 might allow remote attackers to execute arbitrary SQL queries via the cat parameter. 1.1% —
CVE-2024-49132 HIGH 8.1 microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.1% —
CVE-2024-49123 HIGH 8.1 microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.1% —
CVE-2024-49065 MED 5.5 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 1.1% —
CVE-2024-23537 HIGH 8.4 apache fineract Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.9.0, which fixes the issue. 1.1% —
CVE-2023-47701 MED 6.5 ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 266166. 1.1% —
CVE-2023-1192 MED 6.5 linux linux_kernel A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses i 1.1% —
CVE-2018-0831 HIGH 7.8 microsoft windows_10 The Windows kernel in Windows 10 versions 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Kernel Elevation of Privilege Vulnerabilit 1.1% —
CVE-2017-7661 HIGH 8.8 apache cxf_fediz Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3, Jetty 8 and Jetty 9 plugins in Apache CXF Fediz prio 1.1% —
CVE-2017-5573 MED 4.9 citrix xenserver An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can cancel tasks of other administrators. 1.1% —
CVE-2017-5572 MED 6.5 citrix xenserver An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can corrupt the host database. 1.1% —
CVE-2016-6395 MED 5.4 cisco firesight_system_software Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, 1.1% —
CVE-2023-4593 MED 6.5 seattlelab slmail Path traversal vulnerability whose exploitation could allow an authenticated remote user to bypass SecurityManager's intended restrictions and list a parent directory via any filename, such as a multiple ..%2F value affecting the 'dodoc' parameter in the /Mail 1.1% —
CVE-2023-35701 MED 6.6 apache hive Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and it can potentially lead to arbitrary code execution on the machine/endpoint that the JDBC driver (client) is r 1.1% —