58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38019 | HIGH 7.2 | microsoft windows_10_1507 Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2020-3338 | HIGH 7.5 | cisco nx-os A vulnerability in the Protocol Independent Multicast (PIM) feature for IPv6 networks (PIM6) of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to | 1.8% | — |
| CVE-2019-1662 | HIGH 8.2 | cisco prime_collaboration_assurance A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to access the system as a valid user. The vulnerability is due to insufficient authentication | 1.8% | — |
| CVE-2018-6970 | MED 6.5 | vmware horizon_client VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horizon Client (4.x.x and prior before 4.8.1) contain an out-of-bounds read vulnerability in the Message Framework library. Successfully exploiting this issue may allow a less-privilege | 1.8% | — |
| CVE-2011-0037 | HIGH 7.2 | microsoft forefront_client_security Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local use | 1.8% | — |
| CVE-2002-0339 | MED 5.0 | cisco ios Cisco IOS 11.1CC through 12.2 with Cisco Express Forwarding (CEF) enabled includes portions of previous packets in the padding of a MAC level packet when the MAC packet's length is less than the IP level packet length. | 1.8% | — |
| CVE-2024-21111 | HIGH 7.8 | oracle vm_virtualbox Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Orac | 1.8% | — |
| CVE-2020-3141 | HIGH 8.8 | cisco ios_xe Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device. For more information ab | 1.8% | — |
| CVE-2019-10223 | MED 6.5 | kubernetes kube-state-metrics A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata abo | 1.8% | — |
| CVE-2018-0396 | MED 6.1 | cisco unified_communications_manager_im_and_presence_service A vulnerability in the web framework of the Cisco Unified Communications Manager IM and Presence Service software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected | 1.8% | — |
| CVE-2016-9252 | HIGH 7.5 | f5 big-ip_access_policy_manager The Traffic Management Microkernel (TMM) in F5 BIG-IP before 11.5.4 HF3, 11.6.x before 11.6.1 HF2 and 12.x before 12.1.2 does not properly handle minimum path MTU options for IPv6, which allows remote attackers to cause a denial-of-service (DoS) through unspec | 1.8% | — |
| CVE-2022-29379 | CRIT 9.8 | f5 njs Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not p | 1.8% | — |
| CVE-2021-36074 | LOW 3.3 | adobe bridge Adobe Bridge versions 11.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue require | 1.8% | — |
| CVE-2021-36071 | LOW 3.3 | adobe bridge Adobe Bridge versions 11.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue require | 1.8% | — |
| CVE-2021-3050 | HIGH 8.8 | paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 9.0 version 9.0.10 through PAN-OS 9.0.14; PAN-OS 9.1 | 1.8% | — |
| CVE-2021-1580 | MED 6.5 | cisco application_policy_infrastructure_controller Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system. For more informa | 1.8% | — |
| CVE-2019-6602 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP 11.5.1-11.5.8 and 11.6.1-11.6.3, the Configuration Utility login page may not follow best security practices when handling a malicious request. | 1.8% | — |
| CVE-2013-1939 | MED 5.0 | fruux sabredav The HTML\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not properly check path separators in the base path, which allows remote attackers to read arbitrary files via a \ | 1.8% | — |
| CVE-2011-3295 | HIGH 7.8 | cisco ios_xr The NETIO and IPV4_IO processes in Cisco IOS XR 3.8 through 4.1, as used in Cisco Carrier Routing System and other products, allow remote attackers to cause a denial of service (CPU consumption) via crafted network traffic, aka Bug ID CSCti59888. | 1.8% | — |
| CVE-2023-35298 | HIGH 7.5 | microsoft windows_11_21h2 HTTP.sys Denial of Service Vulnerability | 1.8% | — |
| CVE-2023-32084 | HIGH 7.5 | microsoft windows_10_1809 HTTP.sys Denial of Service Vulnerability | 1.8% | — |
| CVE-2020-3572 | HIGH 8.6 | cisco adaptive_security_appliance A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected dev | 1.8% | — |
| CVE-2019-1436 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1440. | 1.8% | — |
| CVE-2018-8140 | MED 6.8 | microsoft windows_10 An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideration for status, aka "Cortana Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10. | 1.8% | — |
| CVE-2016-1387 | CRIT 9.8 | cisco telepresence_tc_software The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8.1.0 in Cisco TelePresence Software mishandles authentication, which allows remote attackers to execute control | 1.8% | — |