58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-41937 | MED 6.1 | apache airflow Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web s | 1.7% | — |
| CVE-2024-21420 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2023-36407 | HIGH 7.8 | microsoft windows_11_21h2 Windows Hyper-V Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2020-35769 | CRIT 9.8 | webmin webmin miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program. | 1.7% | — |
| CVE-2019-15666 | MED 4.4 | debian debian_linux An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory validation. | 1.7% | — |
| CVE-2007-4774 | MED 5.9 | linux linux_kernel The Linux kernel before 2.4.36-rc1 has a race condition. It was possible to bypass systrace policies by flooding the ptraced process with SIGCONT signals, which can can wake up a PTRACED process. | 1.7% | — |
| CVE-2024-30097 | HIGH 8.8 | microsoft windows_10_1507 Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2020-1442 | MED 6.1 | microsoft office_online_server A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request, aka 'Office Web Apps XSS Vulnerability'. | 1.7% | — |
| CVE-2019-0759 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Print Spooler does not properly handle objects in memory, aka 'Windows Print Spooler Information Disclosure Vulnerability'. | 1.7% | — |
| CVE-2018-0118 | MED 6.1 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to perform a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected dev | 1.7% | — |
| CVE-2016-6437 | MED 5.9 | cisco wide_area_application_services A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of disk space. The user would see a performa | 1.7% | — |
| CVE-2015-4286 | MED 5.0 | cisco unified_computing_system_central_software The web framework in Cisco UCS Central Software 1.3(0.99) allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuu41377. | 1.7% | — |
| CVE-2007-4311 | MED 6.8 | linux linux_kernel The xfer_secondary_pool function in drivers/char/random.c in the Linux kernel 2.4 before 2.4.35 performs reseed operations on only the first few bytes of a buffer, which might make it easier for attackers to predict the output of the random number generator, r | 1.7% | — |
| CVE-2005-1020 | HIGH 7.1 | cisco ios Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a domain name when using a TACACS+ server to authenticate, (2) when a new SSH session is in the login phas | 1.7% | — |
| CVE-2021-22049 | CRIT 9.8 | vmware vcenter_server The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request out | 1.7% | — |
| CVE-2020-13922 | MED 6.5 | apache dolphinscheduler Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface. | 1.7% | — |
| CVE-2016-8459 | CRIT 9.8 | linux linux_kernel Possible buffer overflow in storage subsystem. Bad parameters as part of listener responses to RPMB commands could lead to buffer overflow. Product: Android. Versions: Kernel 3.18. Android ID: A-32577972. References: QC-CR#988462. | 1.7% | — |
| CVE-2016-8439 | CRIT 9.8 | linux linux_kernel Possible buffer overflow in trust zone access control API. Buffer overflow may occur due to lack of buffer size checking. Product: Android. Versions: Kernel 3.18. Android ID: A-31625204. References: QC-CR#1027804. | 1.7% | — |
| CVE-2010-4114 | MED 4.3 | hp discovery\&dependency_mapping_inventory Cross-site scripting (XSS) vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.6x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 1.7% | — |
| CVE-2024-49080 | HIGH 8.8 | microsoft windows_10_1507 Windows IP Routing Management Snapin Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2024-29133 | MED 5.4 | apache commons_configuration Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. | 1.7% | — |
| CVE-2010-0312 | MED 5.0 | ibm tivoli_directory_server The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted SecureWay 3.2 Event Registration Request (aka a 1.3.18.0.2.1 | 1.7% | — |
| CVE-2024-39877 | HIGH 8.8 | apache airflow Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according to the Airflow Secur | 1.7% | — |
| CVE-2021-41571 | MED 6.5 | apache pulsar In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API get-message-by-id requires the user to input a topic and a ledger id. The ledger id is a pointer to the data, | 1.7% | — |
| CVE-2020-4876 | HIGH 8.2 | ibm cognos_controller IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Forc | 1.7% | — |