IT
58.135 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.135 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2010-4526 HIGH 7.1 linux linux_kernel Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a socket that is already locked by a user, 2.5%
CVE-2022-26816 MED 6.5 microsoft windows_server_2016 Windows DNS Server Information Disclosure Vulnerability 2.5%
CVE-2020-1067 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists in the way that Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an 2.5%
CVE-2010-1570 HIGH 7.8 cisco customer_response_solution The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), 6.0 before 6.0(1)SR1, and 5.0 before 5.0(2)SR3 allows remote attackers to cause a denial of service (CTI server and Node M 2.5%
CVE-2009-2871 HIGH 7.8 cisco ios Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when SSLVPN sessions, SSH sessions, or IKE encrypted nonces are enabled, allows remote attackers to cause a denial of service (device reload) via a crafted encrypted packet, aka Bug ID CSCsq24002. 2.5%
CVE-2009-2870 HIGH 7.8 cisco ios Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when the Cisco Unified Border Element feature is enabled, allows remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCsx25880. 2.5%
CVE-2018-6960 HIGH 8.8 vmware horizon_daas VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication. Note: In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS. 2.5%
CVE-2010-4368 HIGH 7.5 awstats awstats awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname. 2.5%
CVE-2021-40462 HIGH 7.8 microsoft windows_10 Windows Media Foundation Dolby Digital Atmos Decoders Remote Code Execution Vulnerability 2.5%
CVE-2021-37147 HIGH 7.5 apache traffic_server Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. 2.5%
CVE-2021-31211 HIGH 7.8 microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability 2.5%
CVE-2021-28311 MED 6.5 microsoft windows_10 Windows Application Compatibility Cache Denial of Service Vulnerability 2.5%
CVE-2017-5661 HIGH 7.3 apache formatting_objects_processor In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is r 2.5%
CVE-2024-38068 HIGH 7.5 microsoft windows_10_1507 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability 2.5%
CVE-2024-38067 HIGH 7.5 microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability 2.5%
CVE-2024-38031 HIGH 7.5 microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability 2.5%
CVE-2024-20678 HIGH 8.8 microsoft windows_10_1507 Remote Procedure Call Runtime Remote Code Execution Vulnerability 2.5%
CVE-2018-14611 MED 5.5 debian debian_linux An issue was discovered in the Linux kernel through 4.17.10. There is a use-after-free in try_merge_free_space() when mounting a crafted btrfs image, because of a lack of chunk type flag checks in btrfs_check_chunk_valid in fs/btrfs/volumes.c. 2.5%
CVE-2010-2817 HIGH 7.8 cisco adaptive_security_appliance Unspecified vulnerability in the IKE implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.11), 7.1 and 7.2 before 7.2(5), 8.0 before 8.0(5.15), 8.1 before 8.1(2.44), 8.2 before 8.2(2.10), and 8.3 before 2.5%
CVE-2010-2816 HIGH 7.8 cisco adaptive_security_appliance Unspecified vulnerability in the SIP inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.17), 8.1 before 8.1(2.45), and 8.2 before 8.2(2.13) allows remote attackers to cause a denial of service (dev 2.5%
CVE-2010-2815 HIGH 7.8 cisco adaptive_security_appliance Unspecified vulnerability in the Transport Layer Security (TLS) implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.15), 8.1 before 8.1(2.44), 8.2 before 8.2(2.17), and 8.3 before 8.3 2.5%
CVE-2010-2814 HIGH 7.8 cisco adaptive_security_appliance Unspecified vulnerability in the Transport Layer Security (TLS) implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.15), 8.1 before 8.1(2.44), 8.2 before 8.2(2.17), and 8.3 before 8.3 2.5%
CVE-2010-1581 HIGH 7.8 cisco adaptive_security_appliance Unspecified vulnerability in the Transport Layer Security (TLS) implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.15), 8.1 before 8.1(2.44), 8.2 before 8.2(2.17), and 8.3 before 8.3 2.5%
CVE-2001-0427 HIGH 7.1 cisco vpn_3000_concentrator Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed logi 2.5%
CVE-2025-26651 MED 6.5 microsoft windows_11_22h2 Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. 2.5%