IT
58.089 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.089 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2011-2578 HIGH 7.8 cisco ios Memory leak in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (memory consumption) via malformed SIP packets on a NAT interface, aka Bug ID CSCts12366. 2.7%
CVE-2015-6319 CRIT 9.8 cisco rv_series_router_firmware SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to execute arbitrary SQL commands via a crafted header in an HTTP request, aka Bug ID CSCuv29574. 2.7%
CVE-2022-25329 CRIT 9.8 trendmicro serverprotect Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to 2.7%
CVE-2022-21913 MED 5.3 microsoft windows_10 Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass 2.7%
CVE-2019-11888 CRIT 9.8 golang go Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, which allows attackers to obtain sensitive information or gain privileges. 2.7%
CVE-2025-21230 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.7%
CVE-2007-1209 HIGH 7.2 microsoft windows_vista Use-after-free vulnerability in the Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista does not properly handle connection resources when starting and stopping processes, which allows local users to gain privileges by opening and closing multi 2.7%
CVE-2018-0285 MED 6.5 cisco prime_service_catalog A vulnerability in service logging for Cisco Prime Service Catalog could allow an authenticated, remote attacker to deny service to the user interface. The vulnerability is due to exhaustion of disk space. An attacker could exploit this vulnerability by perfor 2.7%
CVE-2001-1105 HIGH 7.5 cisco icdn RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure. 2.7%
CVE-2025-59230 HIGH 7.8 microsoft windows_10_1507 Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. 2.7%
CVE-2019-18190 CRIT 9.8 trendmicro antivirus\+_security_2020 Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances. 2.7%
CVE-2021-31446 LOW 3.3 foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious f 2.7%
CVE-2020-8283 HIGH 8.8 citrix virtual_apps_and_desktops An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9. 2.7%
CVE-2020-8269 HIGH 8.8 citrix virtual_apps_and_desktops An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9 2.7%
CVE-2002-0046 MED 5.0 linux linux_kernel Linux kernel, and possibly other operating systems, allows remote attackers to read portions of memory via a series of fragmented ICMP packets that generate an ICMP TTL Exceeded response, which includes portions of the memory in the response packet. 2.7%
CVE-2021-26861 HIGH 7.8 microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability 2.7%
CVE-2016-4968 MED 6.5 fortinet fortiwan The linkreport/tmp/admin_global page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to discover administrator cookies via a GET request. 2.7%
CVE-2006-3287 HIGH 7.5 cisco wireless_control_system Cisco Wireless Control System (WCS) for Linux and Windows 4.0(1) and earlier uses a default administrator username "root" and password "public," which allows remote attackers to gain access (aka bug CSCse21391). 2.7%
CVE-2006-3286 HIGH 7.5 cisco wireless_control_system The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(63) stores a hard-coded username and password in plaintext within unspecified files, which allows remote authenticated users to access the database (aka bug CSCsd1595 2.7%
CVE-2006-3285 HIGH 7.5 cisco wireless_control_system The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) uses an undocumented, hard-coded username and password, which allows remote authenticated users to read, and possibly modify, sensitive configuration data (aka bu 2.7%
CVE-2025-13316 HIGH 8.1 lynxtechnology twonky_server Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and 2.7%
CVE-2021-40485 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 2.7%
CVE-2018-17192 MED 6.5 apache nifi The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently appl 2.7%
CVE-2011-3516 HIGH 7.6 sun jdk Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integr 2.7%
CVE-2023-38230 MED 5.5 adobe acrobat Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such a 2.7%