IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2010-4690 MED 5.0 cisco 5500_series_adaptive_security_appliance The Mobile User Security (MUS) service on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) does not properly authenticate HTTP requests from a Web Security appliance (WSA), which might allow remote attackers to obtain se 2.0% —
CVE-2001-1497 LOW 2.1 microsoft ie Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier t 2.0% —
CVE-2019-1806 HIGH 7.7 cisco esw2-350g52dc_firmware A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches could allow an authenticated, remote attack 2.0% —
CVE-2019-12634 HIGH 7.5 cisco integrated_management_controller_supervisor A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) 2.0% —
CVE-2017-6712 HIGH 8.8 cisco elastic_services_controller A vulnerability in certain commands of Cisco Elastic Services Controller could allow an authenticated, remote attacker to elevate privileges to root and run dangerous commands on the server. The vulnerability occurs because a "tomcat" user on the system can ru 2.0% —
CVE-2021-34447 MED 6.8 microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability 2.0% —
CVE-2021-34446 HIGH 8.0 microsoft windows_10 Windows HTML Platforms Security Feature Bypass Vulnerability 2.0% —
CVE-2020-10146 MED 5.7 microsoft teams The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as authentication tokens and to possibly execute arbitrary commands 2.0% —
CVE-2019-6641 MED 6.5 f5 big-ip_access_policy_manager On BIG-IP 12.1.0-12.1.4.1, undisclosed requests can cause iControl REST processes to crash. The attack can only come from an authenticated user; all roles are capable of performing the attack. Unauthenticated users cannot perform this attack. 2.0% —
CVE-2018-4207 HIGH 8.8 apple icloud In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks. 2.0% —
CVE-2017-6599 MED 5.3 cisco ios_xr A vulnerability in Google-defined remote procedure call (gRPC) handling in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash due to a system memory leak, resulting in a denial of 2.0% —
CVE-2016-7462 HIGH 8.5 vmware vrealize_operations The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization. 2.0% —
CVE-2026-21262 HIGH 8.8 microsoft sql_server_2016 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. 2.0% —
CVE-2025-47978 MED 6.5 microsoft windows_server_2022 Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. 2.0% —
CVE-2023-44365 HIGH 7.8 adobe acrobat Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issu 2.0% —
CVE-2023-44338 HIGH 7.8 adobe acrobat Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker cou 2.0% —
CVE-2023-44337 HIGH 7.8 adobe acrobat Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker cou 2.0% —
CVE-2018-5505 MED 5.9 f5 big-ip_analytics On F5 BIG-IP versions 13.1.0 - 13.1.0.3, when ASM and AVR are both provisioned, TMM may restart while processing DNS requests when the virtual server is configured with a DNS profile and the Protocol setting is set to TCP. 2.0% —
CVE-2017-9428 HIGH 7.5 bigtreecms bigtree_cms A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows, allowing attackers to read arbitrary files via ..\ sequences in the directory parameter. 2.0% —
CVE-2022-29158 HIGH 7.5 apache ofbiz Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599 2.0% —
CVE-2021-35221 MED 6.3 solarwinds orion_platform Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings page. 2.0% —
CVE-2019-0202 HIGH 7.5 apache storm The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be access 2.0% —
CVE-2013-7408 HIGH 7.5 f5 big-ip_analytics F5 BIG-IP Analytics 11.x before 11.4.0 uses a predictable session cookie, which makes it easier for remote attackers to have unspecified impact by guessing the value. 2.0% —
CVE-2021-29688 HIGH 7.5 ibm security_identity_manager IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 200102. 2.0% —
CVE-2021-28447 MED 4.4 microsoft windows_10 Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability 2.0% —