58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-30771 | CRIT 9.8 | apache iotdb_web_workbench Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database. This problem is fi | 1.4% | — |
| CVE-2020-27132 | CRIT 9.9 | cisco jabber Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive informati | 1.4% | — |
| CVE-2024-51941 | HIGH 8.8 | apache ambari A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability occurs when processing alert definitions, where malicious input can be injected i | 1.4% | — |
| CVE-2024-24746 | HIGH 7.5 | apache nimble Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: throu | 1.4% | — |
| CVE-2023-26512 | CRIT 9.8 | apache eventmesh-connector-rabbitmq CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq messages. | 1.4% | — |
| CVE-2013-6367 | MED 5.7 | linux linux_kernel The apic_get_tmcct function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via crafted modifications of the TMICT value. | 1.4% | — |
| CVE-2011-1239 | HIGH 7.2 | microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain | 1.4% | — |
| CVE-2009-0320 | MED 4.0 | microsoft windows_server_2003 Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estim | 1.4% | — |
| CVE-2002-0969 | HIGH 7.8 | oracle mysql Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Con | 1.4% | — |
| CVE-2023-22849 | MED 6.1 | apache sling_cms An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in multi | 1.4% | — |
| CVE-2022-40309 | MED 4.3 | apache archiva Users with write permissions to a repository can delete arbitrary directories. | 1.4% | — |
| CVE-2021-41025 | HIGH 7.3 | fortinet fortiweb Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurrent execution using shared resource with i | 1.4% | — |
| CVE-2019-1460 | MED 4.6 | microsoft outlook A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing Vulnerability'. | 1.4% | — |
| CVE-2018-5548 | MED 6.1 | f5 big-ip_access_policy_manager On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using different blocks of cipher | 1.4% | — |
| CVE-2013-6974 | MED 4.3 | cisco secure_access_control_system Cross-site scripting (XSS) vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud89431. | 1.4% | — |
| CVE-2024-37341 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2022-20685 | HIGH 7.5 | cisco cyber_vision A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer overflow while processing Modb | 1.4% | — |
| CVE-2015-6361 | MED 6.5 | cisco dpc3939_wireless_residential_voice_gateway_firmware The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated users to execute arbitrary commands via unspecified fields, aka Bug ID CSCuw86170. | 1.4% | — |
| CVE-2013-5474 | HIGH 7.8 | cisco ios Race condition in the IPv6 virtual fragmentation reassembly (VFR) implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.3 allows remote attackers to cause a denial of service (device reload or hang) via fragmented IPv6 packets, aka Bug ID CSCud6481 | 1.4% | — |
| CVE-2012-2850 | MED 6.8 | google chrome Multiple unspecified vulnerabilities in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allow remote attackers to have an unknown impact via a crafted document. | 1.4% | — |
| CVE-2006-7164 | MED 4.3 | ibm websphere_application_server SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via c | 1.4% | — |
| CVE-2005-3810 | HIGH 7.8 | linux linux_kernel ip_conntrack_proto_icmp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via a message without ICMP ID (ICMP_ID) information, which leads to a null dereference. | 1.4% | — |
| CVE-2005-1058 | HIGH 7.5 | cisco ios Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and m | 1.4% | — |
| CVE-2005-1057 | HIGH 7.5 | cisco ios Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet." | 1.4% | — |
| CVE-2024-43599 | HIGH 8.8 | microsoft windows_10_1507 Remote Desktop Client Remote Code Execution Vulnerability | 1.4% | — |