IT
58.450 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.450 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2023-29362 HIGH 8.8 microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability 1.3% —
CVE-2022-20751 HIGH 8.6 cisco secure_firewall_threat_defense A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause unlimited memory consumption, which could lead to a denial of service (DoS) condition on an aff 1.3% —
CVE-2022-20746 HIGH 8.6 cisco secure_firewall_threat_defense A vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper handling of TCP flows. An atta 1.3% —
CVE-2022-20715 HIGH 8.6 cisco adaptive_security_appliance_software A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affec 1.3% —
CVE-2022-20682 HIGH 8.6 cisco ios_xe A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) 1.3% —
CVE-2020-25772 MED 5.5 trendmicro apex_one An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability t 1.3% —
CVE-2020-25771 MED 5.5 trendmicro apex_one An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability t 1.3% —
CVE-2020-25770 MED 5.5 trendmicro apex_one An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability t 1.3% —
CVE-2020-24565 MED 5.5 trendmicro apex_one An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability t 1.3% —
CVE-2020-24564 MED 5.5 trendmicro apex_one An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability t 1.3% —
CVE-2017-5034 HIGH 8.8 google chrome A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file. 1.3% —
CVE-2013-6704 HIGH 7.1 cisco ios_xe Cisco IOS XE does not properly manage memory for TFTP UDP flows, which allows remote attackers to cause a denial of service (memory consumption) via TFTP (1) client or (2) server traffic, aka Bug IDs CSCuh09324 and CSCty42686. 1.3% —
CVE-2013-6703 HIGH 7.1 cisco ons_15454 The TLS/SSLv3 module on Cisco ONS 15454 controller cards allows remote attackers to cause a denial of service (card reset) via crafted (1) TLS or (2) SSLv3 packets, aka Bug ID CSCuh34787. 1.3% —
CVE-2013-3461 HIGH 7.1 cisco unified_communications_manager Cisco Unified Communications Manager (Unified CM) 8.5(x) and 8.6(x) before 8.6(2a)su3 and 9.x before 9.1(1) does not properly restrict the rate of SIP packets, which allows remote attackers to cause a denial of service (memory and CPU consumption, and service 1.3% —
CVE-2023-49735 HIGH 7.5 apache tiles ** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing user-controlled data 1.3% —
CVE-2023-34060 CRIT 9.8 vmware cloud_director VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network a 1.3% —
CVE-2022-3564 MED 5.5 debian debian_linux A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended 1.3% —
CVE-2014-3402 MED 5.0 cisco intrusion_prevention_system The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote attackers to cause a denial of service ( 1.3% —
CVE-2011-0671 HIGH 8.4 microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain 1.3% —
CVE-2009-1922 MED 6.9 microsoft windows_2000 The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain pr 1.3% —
CVE-2024-39563 HIGH 7.3 juniper junos_space A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance, leading to remote command execution by the 1.3% —
CVE-2024-29066 HIGH 7.2 microsoft windows_server_2008 Windows Distributed File System (DFS) Remote Code Execution Vulnerability 1.3% —
CVE-2024-28746 HIGH 8.1 apache airflow Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.  Users of Apache Airf 1.3% —
CVE-2023-47265 MED 5.4 apache airflow Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript in the parameter description field of the DAG. This Javascript can be executed on the client side of any of th 1.3% —
CVE-2022-37956 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.3% —