58.450 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.450 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-4293 | MED 5.3 | apple icloud A cookie management issue was addressed with improved checks. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6. | 1.3% | — |
| CVE-2018-0020 | HIGH 7.5 | juniper junos Junos OS may be impacted by the receipt of a malformed BGP UPDATE which can lead to a routing process daemon (rpd) crash and restart. Receipt of a repeated malformed BGP UPDATEs can result in an extended denial of service condition for the device. This malform | 1.3% | — |
| CVE-2017-6783 | MED 4.3 | cisco content_security_management_appliance A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover confidential information about the appliances | 1.3% | — |
| CVE-2013-0900 | MED 6.8 | debian debian_linux Race condition in the International Components for Unicode (ICU) functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified oth | 1.3% | — |
| CVE-2026-23455 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit length from the packet, then decrements it by 1 to skip the proto | 1.3% | — |
| CVE-2025-21222 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2025-21221 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2025-21205 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2024-21403 | CRIT 9.0 | microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2021-1629 | MED 6.1 | tableau tableau_server Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users. | 1.3% | — |
| CVE-2019-1282 | MED 5.5 | microsoft windows_10 An information disclosure exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle sandbox checks, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. | 1.3% | — |
| CVE-2019-1274 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. | 1.3% | — |
| CVE-2017-14185 | MED 5.3 | fortinet fortios An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN | 1.3% | — |
| CVE-2010-2826 | HIGH 9.0 | cisco wireless_control_system_software SQL injection vulnerability in Cisco Wireless Control System (WCS) 6.0.x before 6.0.196.0 allows remote authenticated users to execute arbitrary SQL commands via vectors related to the ORDER BY clause of the Client List screens, aka Bug ID CSCtf37019. | 1.3% | — |
| CVE-2023-30447 | MED 5.9 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253436. | 1.3% | — |
| CVE-2023-30446 | MED 5.9 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253361 . | 1.3% | — |
| CVE-2021-21196 | HIGH 8.8 | fedoraproject fedora Heap buffer overflow in TabStrip in Google Chrome on Windows prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1.3% | — |
| CVE-2020-35609 | MED 5.5 | microsoft azure_sphere A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequence of specially crafted ioctl calls can cause a denial of service. An attacker can write shellcode to trigger this vulnerability. | 1.3% | — |
| CVE-2020-1999 | MED 5.3 | paloaltonetworks pan-os A vulnerability exists in the Palo Alto Network PAN-OS signature-based threat detection engine that allows an attacker to communicate with devices in the network in a way that is not analyzed for threats by sending data through specifically crafted TCP packets | 1.3% | — |
| CVE-2020-1194 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists when Windows Registry improperly handles filesystem operations, aka 'Windows Registry Denial of Service Vulnerability'. | 1.3% | — |
| CVE-2016-1976 | MED 5.5 | mozilla firefox Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | 1.3% | — |
| CVE-2011-4022 | MED 5.0 | cisco intrusion_prevention_system The sensor in Cisco Intrusion Prevention System (IPS) 7.0 and 7.1 allows remote attackers to cause a denial of service (file-handle exhaustion and mainApp hang) by making authentication attempts that exceed the configured limit, aka Bug ID CSCto51204. | 1.3% | — |
| CVE-2022-32749 | HIGH 7.5 | apache traffic_server Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server under certain conditions. This issue affects Apache Traffic Server: from 8.0.0 through 9.1.3. | 1.3% | — |
| CVE-2022-24495 | HIGH 7.0 | microsoft windows_10 Windows Direct Show Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2021-31379 | HIGH 7.5 | juniper junos An Incorrect Behavior Order vulnerability in the MAP-E automatic tunneling mechanism of Juniper Networks Junos OS allows an attacker to send certain malformed IPv4 or IPv6 packets to cause a Denial of Service (DoS) to the PFE on the device which is disabled as | 1.3% | — |