IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2021-40700 HIGH 7.8 adobe premiere_elements Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interactio 1.7% —
CVE-2020-0616 MED 5.5 microsoft windows_10 A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'. 1.7% —
CVE-2017-8715 MED 5.3 microsoft windows_10 The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it handles Windows PowerShell sessions, aka "Windows Security Feature Bypass". 1.7% —
CVE-2013-1110 MED 4.0 cisco webex_training_center Cisco WebEx Training Center allow remote authenticated users to bypass intended privilege restrictions and (1) enable or (2) disable training-center recordings via a crafted URL, aka Bug ID CSCzu81065. 1.7% —
CVE-2025-47171 MED 6.7 microsoft 365_apps Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. 1.7% —
CVE-2024-21638 CRIT 9.1 microsoft azure_ipam Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP Address space easily and effectively. By design there is no write access to customers' Azure environments as th 1.7% —
CVE-2023-42781 MED 6.5 apache airflow Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.  This is a different issue than CVE-2023-42663 but leading to similar o 1.7% —
CVE-2022-29405 MED 6.5 apache archiva In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8 1.7% —
CVE-2015-6298 HIGH 9.0 cisco web_security_appliance The admin web interface in Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote authenticated users to obtain root privileges 1.7% —
CVE-2006-0008 HIGH 7.2 microsoft office The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the 1.7% —
CVE-2002-1100 MED 5.0 cisco vpn_3000_concentrator_series_software Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface. 1.7% —
CVE-2002-0952 MED 5.0 cisco optical_networking_systems_software Cisco ONS15454 optical transport platform running ONS 3.1.0 to 3.2.0 allows remote attackers to cause a denial of service (reset) by sending IP packets with non-zero Type of Service (TOS) bits to the Timing Control Card (TCC) LAN interface. 1.7% —
CVE-2002-0545 MED 5.0 cisco aironet_ap340 Cisco Aironet before 11.21 with Telnet enabled allows remote attackers to cause a denial of service (reboot) via a series of login attempts with invalid usernames and passwords. 1.7% —
CVE-2001-0752 MED 5.0 cisco cbos Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via an ICMP ECHO REQUEST (ping) with the IP Record Route option set. 1.7% —
CVE-2001-0058 MED 5.0 cisco broadband_operating_system The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character. 1.7% —
CVE-2000-0268 MED 5.0 cisco 3660_router Cisco IOS 11.x and 12.x allows remote attackers to cause a denial of service by sending the ENVIRON option to the Telnet daemon before it is ready to accept it, which causes the system to reboot. 1.7% —
CVE-2021-1504 HIGH 8.6 cisco adaptive_security_appliance_software Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities a 1.7% —
CVE-2021-1445 HIGH 8.6 cisco adaptive_security_appliance_software Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities a 1.7% —
CVE-2021-1278 HIGH 8.6 cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. 1.7% —
CVE-2017-12309 MED 5.3 cisco email_security_appliance_firmware A vulnerability in the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a HTTP response splitting attack. The vulnerability is due to the failure of the application or its environment to properly sanitize input va 1.7% —
CVE-2016-2809 MED 5.5 mozilla firefox The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by leveraging certain local file execution. 1.7% —
CVE-2015-7323 LOW 3.5 juniper pulse_connect_secure The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 allows remote authenticated users to bypass intended access restrictions and log into arbitrary meetin 1.7% —
CVE-2010-1193 MED 4.3 vmware server Cross-site scripting (XSS) vulnerability in WebAccess in VMware Server 2.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON error messages. 1.7% —
CVE-2009-2277 MED 4.3 vmware esx_server Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "context data." 1.7% —
CVE-2024-38138 HIGH 7.5 microsoft windows_server_2016 Windows Deployment Services Remote Code Execution Vulnerability 1.7% —