IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2024-30090 HIGH 7.0 microsoft windows_10_1507 Microsoft Streaming Service Elevation of Privilege Vulnerability 2.0% —
CVE-2023-29330 HIGH 8.8 microsoft teams Microsoft Teams Remote Code Execution Vulnerability 2.0% —
CVE-2022-25598 HIGH 7.5 apache dolphinscheduler Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher. 2.0% —
CVE-2021-21984 CRIT 9.8 vmware vrealize_business_for_cloud VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious actor with network access may exploit this issue causing unauthorised remote code execution on vRealize Business 2.0% —
CVE-2022-35774 MED 4.9 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 2.0% —
CVE-2021-43255 MED 5.5 microsoft 365_apps Microsoft Office Trust Center Spoofing Vulnerability 2.0% —
CVE-2021-42732 HIGH 7.8 adobe indesign Access of Memory Location After End of Buffer (CWE-788) 2.0% —
CVE-2025-24991 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. 2.0%
CVE-2022-35744 CRIT 9.8 microsoft windows_10_1507 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability 2.0% —
CVE-2022-20801 MED 4.7 cisco rv340_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. Thes 2.0% —
CVE-2020-1595 CRIT 9.9 microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application 2.0% —
CVE-2019-9969 HIGH 7.8 xnview xnview_classic XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x385399. 2.0% —
CVE-2023-33170 HIGH 8.1 fedoraproject fedora ASP.NET and Visual Studio Security Feature Bypass Vulnerability 2.0% —
CVE-2023-21728 HIGH 7.5 microsoft windows_10_1607 Windows Netlogon Denial of Service Vulnerability 2.0% —
CVE-2023-21683 HIGH 7.5 microsoft windows_10_1607 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 2.0% —
CVE-2023-21677 HIGH 7.5 microsoft windows_10_1607 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 2.0% —
CVE-2023-21527 HIGH 7.5 microsoft windows_10_1607 Windows iSCSI Service Denial of Service Vulnerability 2.0% —
CVE-2022-23206 HIGH 7.5 apache traffic_control In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach. 2.0% —
CVE-2021-33746 HIGH 8.0 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 2.0% —
CVE-2016-1295 MED 5.3 cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775. 2.0% —
CVE-2010-1729 MED 4.3 apple safari WebKit.dll in WebKit, as used in Safari.exe 4.531.9.1 in Apple Safari, allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop. 2.0% —
CVE-2008-3817 HIGH 7.8 cisco adaptive_security_appliance_5500_series Memory leak in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 8.0 before 8.0(4) and 8.1 before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via an unspecified sequence of packets, related to 2.0% —
CVE-2008-3811 HIGH 7.8 cisco ios Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabled, allows remote attackers to cause a denial of service (device reload) via segmented SCCP messages, aka Cisco Bug ID CSCsi17020, a different vulnerability tha 2.0% —
CVE-2007-5584 HIGH 7.8 cisco firewall_services_module Unspecified vulnerability in Cisco Firewall Services Module (FWSM) 3.2(3) allows remote attackers to cause a denial of service (device reload) via crafted "data in the control-plane path with Layer 7 Application Inspections." 2.0% —
CVE-2007-5537 HIGH 7.8 cisco unified_callmanager Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote attackers to cause a denial of service (kernel panic) via a flood of SIP INVITE messages to UDP port 5060, which triggers resource ex 2.0% —