58.426 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.426 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2002-1103 | MED 5.0 | cisco vpn_3000_concentrator_series_software Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via (1) malformed or (2) large ISAKMP packets. | 1.4% | — |
| CVE-2024-49124 | HIGH 8.1 | microsoft windows_10_1507 Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-46288 | MED 4.3 | apache airflow Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0. Sensitive configuration information has been exposed to authenticated users with the ability to read configuratio | 1.4% | — |
| CVE-2021-32719 | LOW 3.1 | vmware rabbitmq RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> | 1.4% | — |
| CVE-2016-9879 | HIGH 7.5 | ibm websphere_application_server An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "/" to a re | 1.4% | — |
| CVE-2016-1437 | MED 6.5 | cisco prime_collaboration_deployment SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy92549. | 1.4% | — |
| CVE-2025-49219 | CRIT 9.8 | trendmicro apex_central An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method | 1.4% | — |
| CVE-2025-21306 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2025-21305 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2025-21303 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2025-21302 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2025-21252 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-43598 | HIGH 8.1 | microsoft lightgbm LightGBM Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-22888 | MED 6.5 | apache airflow Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disruption by manipulating the run_id parameter. This vulnerability is considered low since it requires an authenticated user to exploit it. It is | 1.4% | — |
| CVE-2020-3563 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient | 1.4% | — |
| CVE-2020-3560 | HIGH 8.6 | cisco access_points A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device. The vulnerability is due to improper resource management while processing specific packets. An attack | 1.4% | — |
| CVE-2020-3509 | HIGH 8.6 | cisco ios_xe A vulnerability in the DHCP message handler of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the supervisor to crash, which could result in a denial of service (DoS) condition. The vu | 1.4% | — |
| CVE-2020-3369 | HIGH 7.5 | cisco sd-wan_firmware A vulnerability in the deep packet inspection (DPI) engine of Cisco SD-WAN vEdge Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper processing of FTP | 1.4% | — |
| CVE-2019-15262 | HIGH 7.5 | cisco 5508_wireless_lan_controller_firmware A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because t | 1.4% | — |
| CVE-2018-15391 | HIGH 7.5 | cisco remote A vulnerability in certain IPv4 fragment-processing functions of Cisco Remote PHY Software could allow an unauthenticated, remote attacker to impact traffic passing through a device, potentially causing a denial of service (DoS) condition. The vulnerability is | 1.4% | — |
| CVE-1999-0453 | MED 5.0 | cisco router An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP). | 1.4% | — |
| CVE-2021-21179 | HIGH 8.8 | debian debian_linux Use after free in Network Internals in Google Chrome on Linux prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1.4% | — |
| CVE-2011-3109 | HIGH 7.5 | google chrome Google Chrome before 19.0.1084.52 on Linux does not properly perform a cast of an unspecified variable, which allows remote attackers to cause a denial of service or possibly have unknown other impact by leveraging an error in the GTK implementation of the UI. | 1.4% | — |
| CVE-2003-1330 | MED 5.0 | clearswift_limited mailsweeper Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove. | 1.4% | — |
| CVE-2024-43581 | HIGH 7.1 | microsoft windows_10_1809 Microsoft OpenSSH for Windows Remote Code Execution Vulnerability | 1.4% | — |