58.415 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.415 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-36187 | MED 5.3 | fortinet fortiweb A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to cause a denial of service for webserver daemon via crafted HTTP requests | 1.4% | — |
| CVE-2020-16951 | HIGH 8.6 | microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP | 1.4% | — |
| CVE-2015-0610 | MED 4.3 | cisco ios Race condition in the object-group ACL feature in Cisco IOS 15.5(2)T and earlier allows remote attackers to bypass intended access restrictions via crafted network traffic that triggers improper handling of the timing of process switching and Cisco Express For | 1.4% | — |
| CVE-2014-0678 | MED 5.5 | cisco secure_access_control_system The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack sessions and gain privileges via unspecified vectors, aka Bug ID CSCue65951. | 1.4% | — |
| CVE-2010-1254 | MED 6.9 | microsoft open_xml_file_format_converter The installation for Microsoft Open XML File Format Converter for Mac sets insecure ACLs for the /Applications folder, which allows local users to execute arbitrary code by replacing the executable with a Trojan Horse, aka "Mac Office Open XML Permissions Vuln | 1.4% | — |
| CVE-2009-4269 | LOW 2.1 | apache derby The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for loca | 1.4% | — |
| CVE-2009-1126 | HIGH 7.2 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, | 1.4% | — |
| CVE-2009-1125 | HIGH 7.2 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application | 1.4% | — |
| CVE-2009-1124 | HIGH 7.2 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate user-mode pointers in unspecified error conditions, which allows local users to gain privileges via a crafted ap | 1.4% | — |
| CVE-2023-45886 | HIGH 7.5 | f5 big-ip_global_traffic_manager The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute. | 1.4% | — |
| CVE-2023-24858 | HIGH 7.5 | microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1.4% | — |
| CVE-2023-21691 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability | 1.4% | — |
| CVE-2022-20789 | MED 4.9 | cisco unified_communications_manager A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to write arbitrary files on | 1.4% | — |
| CVE-2021-1229 | MED 5.8 | cisco nx-os A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a slow system memory leak, which over time could lead to a denial of service (DoS) condition. This vulnerability is due to im | 1.4% | — |
| CVE-2020-3597 | MED 5.4 | cisco nexus_data_broker A vulnerability in the configuration restore feature of Cisco Nexus Data Broker software could allow an unauthenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient validation of confi | 1.4% | — |
| CVE-2019-12664 | HIGH 7.5 | cisco ios_xe A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs) could allow an unauthenticated, adjacent attacker to pass IPv4 traffic through an ISDN channel prior to succe | 1.4% | — |
| CVE-2018-8233 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers. | 1.4% | — |
| CVE-2016-2065 | HIGH 7.8 | linux linux_kernel sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (out-of | 1.4% | — |
| CVE-1999-1001 | LOW 2.6 | cisco cache_engine Cisco Cache Engine allows a remote attacker to gain access via a null username and password. | 1.4% | — |
| CVE-2025-58098 | HIGH 8.3 | apache http_server Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to up | 1.4% | — |
| CVE-2018-8612 | MED 5.5 | microsoft windows_10 A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values, aka "Connected User Experiences and Telemetry Service Denial of Service Vulnerability." This affects Windows Server 2016, | 1.4% | — |
| CVE-2018-15311 | MED 5.9 | f5 big-ip_access_policy_manager When F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.5.1-11.5.6 is processing specially crafted TCP traffic with the Large Receive Offload (LRO) feature enabled, TMM may crash, leading to a failover event. This vulnerability is not exposed u | 1.4% | — |
| CVE-2017-8018 | HIGH 7.5 | emc appsync EMC AppSync host plug-in versions 3.5 and below (Windows platform only) includes a denial of service (DoS) vulnerability that could potentially be exploited by malicious users to compromise the affected system. | 1.4% | — |
| CVE-2016-10288 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Qualcomm LED driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. P | 1.4% | — |
| CVE-2009-4267 | MED 6.5 | apache juddi The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows parameter. | 1.4% | — |