56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.706 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-0601 | HIGH 8.1 | golang go A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making i | 89.4% | |
| CVE-2023-21547 | HIGH 7.5 | microsoft windows_10_1607 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | 89.3% | — |
| CVE-2015-2342 | HIGH 10.0 | vmware vcenter_server The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol. | 89.0% | — |
| CVE-2006-0026 | MED 6.5 | microsoft internet_information_server Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP). | 88.9% | — |
| CVE-2021-45456 | CRIT 9.8 | apache kylin Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch between what is being checked and what is being used as the shell command argument in DiagnosisService. This may c | 88.9% | — |
| CVE-2023-20073 | MED 5.3 | cisco rv340_firmware A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insuffici | 88.9% | — |
| CVE-2012-0151 | HIGH 7.8 | microsoft windows_7 The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the dig | 88.8% | |
| CVE-2017-8759 | HIGH 7.8 | microsoft .net_framework Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability." | 88.7% | |
| CVE-2023-21769 | HIGH 7.5 | microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 88.7% | — |
| CVE-2022-30216 | HIGH 8.8 | microsoft windows_10 Windows Server Service Tampering Vulnerability | 88.6% | — |
| CVE-2018-8174 | HIGH 7.5 | ransomware microsoft windows_10_1607 A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, | 88.5% | |
| CVE-2020-8193 | MED 6.5 | citrix application_delivery_controller_firmware Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints. | 88.4% | |
| CVE-2020-5398 | HIGH 7.5 | netapp data_availability_services In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the | 88.4% | — |
| CVE-2020-3243 | CRIT 9.8 | cisco ucs_director Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne | 88.4% | — |
| CVE-2026-20127 | CRIT 10.0 | cisco catalyst_sd-wan_manager A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remot | 88.2% | |
| CVE-2012-1454 | MED 4.3 | aladdin esafe The ELF file parser in Dr.Web 5.0.2.03300, eSafe 7.0.17.0, McAfee Gateway (formerly Webwasher) 2010.1C, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file | 88.2% | — |
| CVE-2026-20230 | HIGH 8.6 | cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks thro | 88.2% | |
| CVE-2023-36025 | HIGH 8.8 | microsoft windows_10_1507 Windows SmartScreen Security Feature Bypass Vulnerability | 88.2% | |
| CVE-2014-1776 | CRIT 9.8 | microsoft internet_explorer Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in | 88.0% | |
| CVE-2022-41622 | HIGH 8.8 | f5 big-ip_access_policy_manager In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 88.0% | — |
| CVE-2003-0718 | MED 5.0 | microsoft internet_information_server The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a l | 87.9% | — |
| CVE-2024-26256 | HIGH 7.8 | fedoraproject fedora Libarchive Remote Code Execution Vulnerability | 87.9% | — |
| CVE-2024-36104 | CRIT 9.1 | apache ofbiz Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue. | 87.9% | — |
| CVE-2020-27131 | HIGH 8.1 | cisco security_manager Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. These vulnerabilities are due to insecure deserialization | 87.7% | — |
| CVE-2021-21973 | MED 5.3 | vmware cloud_foundation The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter | 87.6% |