58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-44645 | HIGH 8.8 | apache linkis In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source and maliciou | 1.9% | — |
| CVE-2022-20812 | CRIT 9.0 | cisco expressway Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks o | 1.9% | — |
| CVE-2021-41767 | MED 6.5 | apache guacamole Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact w | 1.9% | — |
| CVE-2018-15466 | MED 5.3 | cisco policy_suite_for_mobile A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacker would need to have access to the inter | 1.9% | — |
| CVE-2017-5660 | HIGH 8.6 | apache traffic_server There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used. | 1.9% | — |
| CVE-2015-5167 | MED 6.5 | apache ranger The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrictions via the REST API. | 1.9% | — |
| CVE-2026-41096 | CRIT 9.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. | 1.9% | — |
| CVE-2021-1479 | HIGH 7.8 | cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these v | 1.9% | — |
| CVE-2024-49107 | HIGH 7.3 | microsoft windows_10_1507 WmsRepair Service Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2020-17516 | HIGH 7.5 | apache cassandra Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A misconfigured node or a malicious user can | 1.9% | — |
| CVE-2018-4194 | HIGH 8.8 | apple icloud In iOS before 11.4, iCloud for Windows before 7.5, watchOS before 4.3.1, iTunes before 12.7.5 for Windows, and macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation. | 1.9% | — |
| CVE-2018-17202 | HIGH 7.5 | apache commons_imaging Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note that Apache Sanselan (incubating) was renamed to Apache Commons Imaging. | 1.9% | — |
| CVE-2018-17201 | HIGH 7.5 | apache commons_imaging Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note that Apache Sanselan (incubating) was renamed to Apache Commons Imaging. | 1.9% | — |
| CVE-2016-1382 | HIGH 7.5 | cisco web_security_appliance_\(wsa\) Cisco AsyncOS before 8.5.3-069 and 8.6 through 8.8 on Web Security Appliance (WSA) devices mishandles memory allocation for HTTP requests, which allows remote attackers to cause a denial of service (proxy-process reload) via a crafted request, aka Bug ID CSCuu | 1.9% | — |
| CVE-2016-1369 | HIGH 7.5 | cisco asa_with_firepower_services The Adaptive Security Appliance (ASA) 5585-X FirePOWER Security Services Processor (SSP) module for Cisco ASA with FirePOWER Services 5.3.1 through 6.0.0 misconfigures kernel logging, which allows remote attackers to cause a denial of service (resource consump | 1.9% | — |
| CVE-2015-6421 | HIGH 7.5 | cisco wide_area_application_services cifs-ao in the CIFS optimization functionality on Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) devices 5.x before 5.3.5d and 5.4 and 5.5 before 5.5.3 allows remote attackers to cause a denial of service (resource consumption and device r | 1.9% | — |
| CVE-2015-6320 | HIGH 7.5 | cisco aironet_access_point_software The IP ingress packet handler on Cisco Aironet 1800 devices with software 8.1(112.3) and 8.1(112.4) allows remote attackers to cause a denial of service via a crafted header in an IP packet, aka Bug ID CSCuv63138. | 1.9% | — |
| CVE-2015-6312 | HIGH 7.5 | dell emc_powerscale_onefs Cisco TelePresence Server 3.1 on 7010, Mobility Services Engine (MSE) 8710, Multiparty Media 310 and 320, and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (device reload) via malformed STUN packets, aka Bug ID CSCuv01348. | 1.9% | — |
| CVE-2007-1337 | HIGH 7.8 | vmware workstation The virtual machine process (VMX) in VMware Workstation before 5.5.4 does not properly read state information when moving from the ACPI sleep state to the run state, which allows attackers to cause a denial of service (virtual machine reboot) via unknown vecto | 1.9% | — |
| CVE-2024-46901 | LOW 3.1 | apache subversion Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. All versi | 1.9% | — |
| CVE-2021-31984 | HIGH 7.6 | microsoft power_bi_report_server Power BI Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2020-3421 | HIGH 8.6 | cisco ios_xe Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload or stop forwarding traffic through the firewall. The vulnerabilities are due to incomplete handli | 1.9% | — |
| CVE-2022-41158 | HIGH 7.2 | eyoom eyoom_builder Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A remote attacker could exploit the vulnerability to execute or inject malicious code. | 1.9% | — |
| CVE-2022-26829 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-26822 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 1.9% | — |