58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-25173 | HIGH 8.0 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-25172 | HIGH 8.0 | microsoft windows_server_2012 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2024-26174 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 0.9% | — |
| CVE-2022-29149 | HIGH 7.8 | microsoft azure_automation_state_configuration Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2022-23022 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.1.x before 16.1.2, when an HTTP profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are | 0.9% | — |
| CVE-2022-23021 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.1.x before 16.1.2, when any of the following configurations are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate: HTTP redirect rule in an LTM policy, BIG-IP APM Access Pr | 0.9% | — |
| CVE-2022-23019 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can caus | 0.9% | — |
| CVE-2022-23018 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager On BIG-IP AFM version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and 13.1.x beginning in 13.1.3.4, when a virtual server is configured with both HTTP protocol security and HTTP Proxy Connect profiles, undisclosed requests can cause t | 0.9% | — |
| CVE-2022-23017 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when a virtual server is configured with a DNS profile with the Rapid Response Mode setting enabled and is configured on a BIG-IP system, undisclo | 0.9% | — |
| CVE-2022-23016 | HIGH 7.5 | f5 big-ip_access_policy_manager On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP SSL Forward Proxy with TLS 1.3 is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have | 0.9% | — |
| CVE-2022-23012 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP versions 15.1.x before 15.1.4.1 and 14.1.x before 14.1.4.5, when the HTTP/2 profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached En | 0.9% | — |
| CVE-2022-22198 | HIGH 7.5 | juniper junos An Access of Uninitialized Pointer vulnerability in the SIP ALG of Juniper Networks Junos OS allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). Continued receipt of these specific packets will cause a sustained Denial of Servi | 0.9% | — |
| CVE-2021-38941 | HIGH 8.1 | ibm cloud_pak_for_multicloud_management_monitoring IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable to host information leakage or destruction if unauthorized access to these containers could execute arbitrary commands. IBM X-Force ID: 21104 | 0.9% | — |
| CVE-2021-1416 | MED 6.5 | cisco identity_services_engine Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information. These vulnerabilities are due to improper enforcement of administrator privilege levels for sens | 0.9% | — |
| CVE-2020-27124 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the SSL/TLS handler of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause the affected device to reload unexpectedly, leading to a denial of service (DoS) condition. The vulnerabil | 0.9% | — |
| CVE-2020-1547 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted applicat | 0.9% | — |
| CVE-2023-20857 | MED 6.8 | vmware workspace_one_content VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode. | 0.9% | — |
| CVE-2023-20006 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote att | 0.9% | — |
| CVE-2022-44729 | HIGH 7.1 | apache xml_graphics_batik Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource | 0.9% | — |
| CVE-2022-40141 | HIGH 7.5 | trendmicro apex_one A vulnerability in Trend Micro Apex One and Apex One as a Service could allow an attacker to intercept and decode certain communication strings that may contain some identification attributes of a particular Apex One server. | 0.9% | — |
| CVE-2022-26933 | MED 5.5 | microsoft windows_10 Windows NTFS Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-29723 | HIGH 7.5 | ibm sterling_external_authentication_server IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-ForceID: 201100. | 0.9% | — |
| CVE-2021-29722 | HIGH 7.5 | ibm sterling_external_authentication_server IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201095. | 0.9% | — |
| CVE-2021-29488 | MED 4.3 | sabnzbd sabnzbd SABnzbd is an open source binary newsreader. A vulnerability was discovered in SABnzbd that could trick the `filesystem.renamer()` function into writing downloaded files outside the configured Download Folder via malicious PAR2 files. A patch was released as p | 0.9% | — |
| CVE-2021-23053 | MED 5.3 | f5 big-ip_advanced_web_application_firewall On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP Advanced WAF or BIG-IP ASM is enabled on a virtual server and the virtual server is under brute force attack, the MySQL datab | 0.9% | — |