58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-4875 | HIGH 8.2 | ibm cognos_controller IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Forc | 1.7% | — |
| CVE-2019-0007 | CRIT 9.3 | juniper junos The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible to a family of attacks which rely on the use of predictable IP ID sequence numbers as their base method of att | 1.7% | — |
| CVE-2024-21380 | HIGH 8.0 | microsoft dynamics_365_business_central Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability | 1.7% | — |
| CVE-2022-27008 | HIGH 7.5 | f5 njs nginx njs 0.7.2 is vulnerable to Buffer Overflow. Type confused in Array.prototype.concat() when a slow array appended element is fast array. | 1.7% | — |
| CVE-2020-16985 | MED 6.2 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 1.7% | — |
| CVE-2018-8428 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 1.7% | — |
| CVE-2018-13093 | MED 5.5 | linux linux_kernel An issue was discovered in fs/xfs/xfs_icache.c in the Linux kernel through 4.17.3. There is a NULL pointer dereference and panic in lookup_slow() on a NULL inode->i_ops pointer when doing pathwalks on a corrupted xfs image. This occurs because of a lack of pro | 1.7% | — |
| CVE-2014-3822 | MED 5.4 | juniper junos Juniper Junos 11.4 before 11.4R8, 12.1 before 12.1R5, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.1X46 before 12.1X46-D10, and 12.1X47 before 12.1X47-D10 on SRX Series devices, allows remote attackers to cause a denial of service (flowd crash) v | 1.7% | — |
| CVE-2012-4083 | MED 4.0 | cisco unified_computing_system Multiple buffer overflows in the administrative web interface in Cisco Unified Computing System (UCS) allow remote authenticated users to cause a denial of service (memory corruption and session termination) via long string values for unspecified parameters, a | 1.7% | — |
| CVE-2009-2868 | HIGH 7.8 | cisco ios Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997. | 1.7% | — |
| CVE-2003-0959 | HIGH 10.0 | Multiple integer overflows in the 32bit emulation for AMD64 architectures in Linux 2.4 kernel before 2.4.21 allows attackers to cause a denial of service or gain root privileges via unspecified vectors that trigger copy_from_user function calls with improper l | 1.7% | — |
| CVE-2022-30154 | MED 5.3 | microsoft windows_10 Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2019-18625 | HIGH 7.5 | debian debian_linux An issue was discovered in Suricata 5.0.0. It was possible to bypass/evade any tcp based signature by faking a closed TCP session using an evil server. After the TCP SYN packet, it is possible to inject a RST ACK and a FIN ACK packet with a bad TCP Timestamp o | 1.7% | — |
| CVE-2019-0886 | MED 6.8 | microsoft windows_10 An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'. | 1.7% | — |
| CVE-2005-0060 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application. | 1.7% | — |
| CVE-2003-1307 | MED 4.3 | apache http_server The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connecti | 1.7% | — |
| CVE-2024-31865 | MED 6.5 | apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users ar | 1.7% | — |
| CVE-2023-21543 | HIGH 8.1 | microsoft windows_10_1607 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2018-0111 | MED 5.3 | cisco webex_meetings_server A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to gain information to conduct additional reconnaissance attacks. The vu | 1.7% | — |
| CVE-2015-0084 | LOW 2.1 | microsoft windows_7 The Task Scheduler in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to bypass intended restri | 1.7% | — |
| CVE-2013-2553 | HIGH 7.2 | microsoft windows_7 Unspecified vulnerability in the kernel in Microsoft Windows 7 allows local users to gain privileges via unknown vectors, as demonstrated by Nils and Jon of MWR Labs during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0912. | 1.7% | — |
| CVE-2005-3221 | MED 5.1 | fortinet fortinet_antivirus Multiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by prod | 1.7% | — |
| CVE-2025-24999 | HIGH 8.8 | microsoft sql_server_2016 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.7% | — |
| CVE-2022-35767 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2022-35766 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.7% | — |