58.352 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.352 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-12267 | MED 5.3 | cisco virtual_wide_area_application_services A vulnerability in the Independent Computing Architecture (ICA) accelerator feature for the Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an ICA application optimization-related process to restart, resulti | 1.6% | — |
| CVE-2017-0613 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first require | 1.6% | — |
| CVE-2016-1484 | HIGH 7.5 | cisco webex_meetings_server Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspecified vectors, aka Bug ID CSCuy92724. | 1.6% | — |
| CVE-2025-21301 | MED 6.5 | microsoft windows_10_1507 Windows Geolocation Service Information Disclosure Vulnerability | 1.6% | — |
| CVE-2023-50298 | HIGH 7.5 | apache solr Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a | 1.6% | — |
| CVE-2022-31705 | HIGH 8.2 | vmware esxi VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's | 1.6% | — |
| CVE-2021-26629 | HIGH 8.8 | tobesoft xplatform A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..\’. | 1.6% | — |
| CVE-2020-4771 | MED 5.3 | ibm spectrum_protect_operations_center IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication of a websocket endpoint. By using known tools to subscribe to the webs | 1.6% | — |
| CVE-2018-0018 | HIGH 7.5 | juniper junos On SRX Series devices during compilation of IDP policies, an attacker sending specially crafted packets may be able to bypass firewall rules, leading to information disclosure which an attacker may use to gain control of the target device or other internal dev | 1.6% | — |
| CVE-2017-8675 | HIGH 7.0 | microsoft windows_10 The Windows Kernel-Mode Drivers component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privil | 1.6% | — |
| CVE-2026-20875 | HIGH 7.5 | microsoft windows_10_1607 Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | 1.6% | — |
| CVE-2023-35622 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 1.6% | — |
| CVE-2023-33934 | CRIT 9.1 | apache traffic_server Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1. | 1.6% | — |
| CVE-2021-34701 | MED 4.3 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unifie | 1.6% | — |
| CVE-2020-3181 | MED 6.5 | cisco email_security_appliance A vulnerability in the malware detection functionality in Cisco Advanced Malware Protection (AMP) in Cisco AsyncOS Software for Cisco Email Security Appliances (ESAs) could allow an unauthenticated remote attacker to exhaust resources on an affected device. Th | 1.6% | — |
| CVE-2020-3165 | HIGH 8.2 | cisco nx-os A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication in Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass MD5 authentication and establish a BGP connection with the device. Th | 1.6% | — |
| CVE-2019-1853 | MED 4.8 | cisco anyconnect_secure_mobility_client A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenticated, remote attacker to read sensitive information on an affected system. The vulnerability exists because the affected software performs | 1.6% | — |
| CVE-2019-0229 | HIGH 8.8 | apache airflow A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vulnerable to cross-site request forgery attacks. | 1.6% | — |
| CVE-2019-0044 | HIGH 7.5 | juniper junos Receipt of a specific packet on the out-of-band management interface fxp0 may cause the system to crash and restart (vmcore). By continuously sending a specially crafted packet to the fxp0 interface, an attacker can repetitively crash the rpd process causing p | 1.6% | — |
| CVE-2018-0284 | MED 6.5 | cisco meraki_mr_24_firmware A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local sta | 1.6% | — |
| CVE-2018-0140 | MED 6.5 | cisco content_security_management_appliance A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated, remote attacker to download any message from the spam quarantine by modifying browser string information. The | 1.6% | — |
| CVE-2017-0169 | MED 5.4 | microsoft windows_8.1 An information disclosure vulnerability exists when Windows Hyper-V running on a Windows 8.1, Windows Server 2012. or Windows Server 2012 R2 host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Hyp | 1.6% | — |
| CVE-2013-3460 | HIGH 7.8 | cisco unified_communications_manager Memory leak in Cisco Unified Communications Manager (Unified CM) 8.5(x) before 8.5(1)su6, 8.6(x) before 8.6(2a)su3, and 9.x before 9.1(1) allows remote attackers to cause a denial of service (service disruption) via a high rate of UDP packets, aka Bug ID CSCub | 1.6% | — |
| CVE-2007-2896 | MED 4.3 | symantec enterprise_security_manager Race condition in the Symantec Enterprise Security Manager (ESM) 6.5.3 managers and agents on Windows before 20070524 allows remote attackers to cause a denial of service (CPU consumption and application hang) via certain network scans to ESM ports. | 1.6% | — |
| CVE-2010-1986 | MED 5.0 | mozilla firefox Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption and application crash) via JavaScript code that creates multiple arrays containing elements with long string values, and then appends long strings | 1.6% | — |