57.469 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.469 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-12235 | HIGH 7.5 | cisco ios A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) co | 7.1% | |
| CVE-2017-12234 | HIGH 7.5 | cisco ios Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) conditio | 7.1% | |
| CVE-2017-12233 | HIGH 7.5 | cisco ios Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) conditio | 7.1% | |
| CVE-2017-12231 | HIGH 7.5 | cisco ios A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due | 7.1% | |
| CVE-2016-4249 | HIGH 8.8 | adobe flash_player Heap-based buffer overflow in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors. | 7.1% | — |
| CVE-2005-3481 | HIGH 9.3 | cisco ios Cisco IOS 12.0 to 12.4 might allow remote attackers to execute arbitrary code via a heap-based buffer overflow in system timers. NOTE: this issue does not correspond to a specific vulnerability, rather a general weakness that only increases the feasibility of | 7.1% | — |
| CVE-2015-4001 | HIGH 9.0 | linux linux_kernel Integer signedness error in the oz_hcd_get_desc_cnf function in drivers/staging/ozwpan/ozhcd.c in the OZWPAN driver in the Linux kernel through 4.0.5 allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a c | 7.1% | — |
| CVE-2017-11502 | CRIT 9.8 | cisco dpc3928ad_docsis_wireless_router_firmware Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321. | 7.1% | — |
| CVE-2009-2698 | HIGH 7.8 | canonical ubuntu_linux The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involvi | 7.1% | — |
| CVE-2025-53766 | CRIT 9.8 | microsoft 365_copilot Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 7.1% | — |
| CVE-2015-5344 | CRIT 9.8 | apache camel The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request. | 7.1% | — |
| CVE-2018-0154 | HIGH 7.5 | cisco ios A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is d | 7.1% | |
| CVE-2014-0491 | HIGH 10.0 | adobe adobe_air Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK & Compiler before 4.0.0.1390 allow attackers | 7.1% | — |
| CVE-2024-38080 | HIGH 7.8 | microsoft windows_11_21h2 Windows Hyper-V Elevation of Privilege Vulnerability | 7.1% | |
| CVE-2019-0833 | MED 6.5 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka 'Microsoft Edge Information Disclosure Vulnerability'. | 7.1% | — |
| CVE-2025-59922 | HIGH 7.2 | fortinet forticlientems An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS | 7.1% | — |
| CVE-2018-1040 | MED 5.3 | microsoft windows_10 A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs hashing, aka "Windows Code Integrity Module Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 200 | 7.1% | — |
| CVE-2011-4693 | HIGH 9.3 | adobe flash_player Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF file, as demonstrated by the first of two vulnerabilities exploited by the Intevydis vd_adobe_fp module in V | 7.1% | — |
| CVE-2014-3574 | MED 4.3 | apache poi Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack. | 7.1% | — |
| CVE-2002-2008 | MED 5.0 | apache tomcat Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message. | 7.1% | — |
| CVE-2016-3292 | MED 5.0 | microsoft internet_explorer Microsoft Internet Explorer 10 and 11 mishandles integrity settings and zone settings, which allows remote attackers to bypass a sandbox protection mechanism via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability." | 7.1% | — |
| CVE-2018-8175 | MED 6.5 | microsoft windows_10 An denial of service vulnerability exists when Windows NT WEBDAV Minirdr attempts to query a WEBDAV directory, aka "WEBDAV Denial of Service Vulnerability." This affects Windows 10 Servers, Windows 10. | 7.1% | — |
| CVE-2016-0783 | HIGH 7.5 | apache openmeetings The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attackers to reset arbitrary user passwords by leveraging knowledge of a user name and the current system time. | 7.1% | — |
| CVE-2000-1022 | HIGH 7.5 | cisco pix_firewall_software The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands. | 7.1% | — |
| CVE-2016-7863 | HIGH 8.8 | adobe flash_player Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution. | 7.1% | — |