58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-39180 | MED 4.0 | linux linux_kernel A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of | 1.4% | — |
| CVE-2023-35302 | HIGH 8.8 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2005-3753 | HIGH 7.8 | linux linux_kernel Linux kernel before after 2.6.12 and before 2.6.13.1 might allow attackers to cause a denial of service (Oops) via certain IPSec packets that cause alignment problems in standard multi-block cipher processors. NOTE: it is not clear whether this issue can be t | 1.4% | — |
| CVE-2024-38212 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2021-21706 | MED 5.3 | php php In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be | 1.4% | — |
| CVE-2018-6980 | HIGH 7.2 | vmware vrealize_log_insight VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method. Successful exploitation of this issue may allow Admin users with view only permission to perform cer | 1.4% | — |
| CVE-2018-4347 | HIGH 7.8 | apple icloud A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7. | 1.4% | — |
| CVE-2019-1877 | MED 6.5 | cisco enterprise_chat_and_email A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through chat sessions. The vulnerability is due to insufficient authentication mechanisms on the file download functio | 1.4% | — |
| CVE-2017-8716 | MED 5.3 | microsoft windows_10 Windows Control Flow Guard in Microsoft Windows 10 Version 1703 allows an attacker to run a specially crafted application to bypass Control Flow Guard, due to the way that Control Flow Guard handles objects in memory, aka "Windows Security Feature Bypass Vulne | 1.4% | — |
| CVE-2015-0700 | MED 6.8 | cisco secure_access_control_server_solution_engine Cross-site request forgery (CSRF) vulnerability in the Dashboard page in the monitoring-and-report section in Cisco Secure Access Control Server Solution Engine before 5.5(0.46.5) allows remote attackers to hijack the authentication of arbitrary users, aka Bug | 1.4% | — |
| CVE-2025-21297 | HIGH 8.1 | microsoft windows_server_2008 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-43517 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ActiveX Data Objects Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-36013 | MED 6.5 | microsoft powershell PowerShell Information Disclosure Vulnerability | 1.4% | — |
| CVE-2022-41035 | MED 5.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.4% | — |
| CVE-2022-36124 | HIGH 7.5 | apache avro It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apa | 1.4% | — |
| CVE-2020-0837 | MED 5.0 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi-factor authentication requests. An attacker who successfully exploited this vulnerability could bypass some, but not all, of the authent | 1.4% | — |
| CVE-2019-4656 | MED 6.5 | ibm mq IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulnerable to a denial of service attack that would allow an authenticated user to crash the queue and require a restart due to an error processing error messages. IBM X-Force ID: 17096 | 1.4% | — |
| CVE-2018-0134 | MED 5.3 | cisco mobility_services_engine A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to determine whether a subscriber username is valid. The vulnerability occurs because the Cisco Policy Suite RADIUS server component retur | 1.4% | — |
| CVE-2017-5054 | HIGH 8.8 | google chrome An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to obtain heap memory contents via a crafted HTML page. | 1.4% | — |
| CVE-2017-0623 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the HTC bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as High because it first requires compromising a privileged process. Pr | 1.4% | — |
| CVE-2017-0622 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Goodix touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged proc | 1.4% | — |
| CVE-2014-0665 | MED 4.0 | cisco identity_services_engine_software The RBAC implementation in Cisco Identity Services Engine (ISE) Software does not properly verify privileges for support-bundle downloads, which allows remote authenticated users to obtain sensitive information via a download action, as demonstrated by obtaini | 1.4% | — |
| CVE-2017-5426 | MED 5.3 | mozilla firefox On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox are run protected only by the running filter which is typical | 1.4% | — |
| CVE-2005-3400 | MED 5.0 | fortinet fortinet Multiple interpretation error in Fortinet 2.48.0.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type | 1.4% | — |
| CVE-2001-0429 | MED 5.0 | cisco catos Cisco Catalyst 5000 series switches 6.1(2) and earlier will forward an 802.1x frame on a Spanning Tree Protocol (STP) blocked port, which causes a network storm and a denial of service. | 1.4% | — |