58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.046 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1337 | HIGH 7.2 | cisco rv016_multi-wan_vpn_router_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpect | 2.9% | — |
| CVE-2020-9491 | HIGH 7.5 | apache nifi In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communication such as cluster request replication | 2.9% | — |
| CVE-2020-36278 | HIGH 7.5 | debian debian_linux Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c. | 2.9% | — |
| CVE-2022-26934 | MED 6.5 | microsoft 365_apps Windows Graphics Component Information Disclosure Vulnerability | 2.9% | — |
| CVE-2015-0713 | HIGH 9.0 | cisco telepresence_advanced_media_gateway The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2(1.94 | 2.9% | — |
| CVE-2012-1821 | MED 5.0 | symantec endpoint_protection The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.700x on Windows Server 2003 allows remote attackers to cause a denial of service (web-server outage, or daemon crash or hang) via a flood | 2.9% | — |
| CVE-2022-23259 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2017-0241 | MED 5.3 | microsoft edge An elevation of privilege vulnerability exists when Microsoft Edge renders a domain-less page in the URL, which could allow Microsoft Edge to perform actions in the context of the Intranet Zone and access functionality that is not typically available to the br | 2.9% | — |
| CVE-2020-10515 | CRIT 9.8 | starface unified_communication_\&_collaboration_client STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006. | 2.9% | — |
| CVE-2016-6386 | HIGH 7.5 | cisco ios_xe Cisco IOS XE 3.1 through 3.17 and 16.1 on 64-bit platforms allows remote attackers to cause a denial of service (data-structure corruption and device reload) via fragmented IPv4 packets, aka Bug ID CSCux66005. | 2.9% | — |
| CVE-2016-6379 | HIGH 7.5 | cisco ios Cisco IOS 12.2 and IOS XE 3.14 through 3.16 and 16.1 allow remote attackers to cause a denial of service (device reload) via crafted IP Detail Record (IPDR) packets, aka Bug ID CSCuu35089. | 2.9% | — |
| CVE-2016-6355 | HIGH 7.5 | cisco ios_xr Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows remote attackers to cause a denial of service (control-plane protocol outage) via crafted fragmented packets, aka Bug ID CSCux26791. | 2.9% | — |
| CVE-2016-1466 | HIGH 7.5 | cisco unified_communications_manager_im_and_presence_service Cisco Unified Communications Manager IM and Presence Service 9.1(1) SU6, 9.1(1) SU6a, 9.1(1) SU7, 10.5(2) SU2, 10.5(2) SU2a, 11.0(1) SU1, and 11.5(1) allows remote attackers to cause a denial of service (sipd process restart) via crafted headers in a SIP packe | 2.9% | — |
| CVE-2016-1312 | HIGH 7.5 | cisco asa_5500_csc-ssm_firmware The HTTPS inspection engine in the Content Security and Control Security Services Module (CSC-SSM) 6.6 before 6.6.1164.0 for Cisco ASA 5500 devices allows remote attackers to cause a denial of service (memory consumption or device reload) via a flood of HTTPS | 2.9% | — |
| CVE-2018-0745 | MED 4.7 | microsoft windows_10 The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Windows Information Disclosure Vulnerability". This CVE I | 2.9% | — |
| CVE-2015-6531 | HIGH 7.8 | paloaltonetworks pan-os Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file. | 2.9% | — |
| CVE-2023-29324 | MED 6.5 | microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability | 2.9% | — |
| CVE-2023-28293 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 2.9% | — |
| CVE-2020-36281 | HIGH 7.5 | debian debian_linux Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c. | 2.9% | — |
| CVE-2020-3144 | CRIT 9.8 | cisco rv110w_firmware A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass authenti | 2.9% | — |
| CVE-2020-1936 | MED 6.1 | apache ambari A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4. | 2.9% | — |
| CVE-2026-55957 | HIGH 7.3 | apache tomcat Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0- | 2.9% | — |
| CVE-2016-1279 | CRIT 9.8 | juniper junos J-Web in Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D25, 13.3 before 13.3R10, 13.3R9 before 13.3R9-S1, 14.1 before 14.1R7, 14.1X53 before 14.1X53-D35, 14.2 before 14.2R6, 15.1 befor | 2.9% | — |
| CVE-2014-8019 | MED 5.0 | cisco enterprise_content_delivery_system Directory traversal vulnerability in Cisco Enterprise Content Delivery System (ECDS) allows remote attackers to read arbitrary files via a crafted URL, aka Bug ID CSCuo90148. | 2.9% | — |
| CVE-2022-26936 | MED 6.5 | microsoft windows_10 Windows Server Service Information Disclosure Vulnerability | 2.9% | — |