58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2012-0338 | MED 5.0 | cisco ios Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish SSH connections from arbitrary source IP addresses via a standard SSH client, aka Bug ID CSCsv8 | 1.3% | — |
| CVE-2026-24300 | CRIT 9.8 | microsoft azure_front_door Azure Front Door Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2021-36152 | CRIT 9.8 | apache gobblin Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.0. Users should update to version 0.16.0 which addresses this issue. | 1.3% | — |
| CVE-2020-16984 | HIGH 7.3 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.3% | — |
| CVE-2019-10099 | HIGH 7.5 | apache spark Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are fetched to disk (controlled by spark.maxRemoteBlockSizeFetchToMem); in SparkR, usi | 1.3% | — |
| CVE-2019-0936 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0734. | 1.3% | — |
| CVE-2017-5113 | HIGH 8.8 | debian debian_linux Math overflow in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1.3% | — |
| CVE-2026-88772 | HIGH 8.1 | citrix netscaler_application_delivery_controller Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote | 1.3% | |
| CVE-2025-61733 | HIGH 7.5 | apache kylin Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upgrade to version 5.0.3, which fixes the issue. | 1.3% | — |
| CVE-2020-7882 | HIGH 7.5 | hancom anysign4pc Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../') | 1.3% | — |
| CVE-2017-2311 | MED 5.3 | juniper junos_space On Juniper Networks Junos Space versions prior to 16.1R1, an unauthenticated remote attacker with network access to Junos space device can easily create a denial of service condition. | 1.3% | — |
| CVE-2017-12364 | MED 6.5 | cisco prime_service_catalog A SQL Injection vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unauthorized Structured Query Language (SQL) queries. The vulnerability is due to a failure to validate user-supplied i | 1.3% | — |
| CVE-2017-0246 | HIGH 7.0 | microsoft windows_10 The Graphics Component in the kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges | 1.3% | — |
| CVE-2016-6426 | HIGH 7.5 | cisco unified_contact_center_express The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, | 1.3% | — |
| CVE-2015-4550 | MED 4.3 | cisco adaptive_security_appliance_software The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM Integrity Check Value (ICV) octets, which makes it easier for man-in-the-middle attackers to spoof IPSec a | 1.3% | — |
| CVE-2024-49035 | HIGH 8.7 | microsoft partner_center An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. | 1.3% | |
| CVE-2023-33159 | HIGH 8.8 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 1.3% | — |
| CVE-2022-42466 | MED 6.1 | apache isis Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this w | 1.3% | — |
| CVE-2020-1419 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1389, CVE-2020-1426. | 1.3% | — |
| CVE-2018-0817 | HIGH 7.0 | microsoft windows_10 The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 al | 1.3% | — |
| CVE-2018-0815 | HIGH 7.0 | microsoft windows_7 The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Windows 7 SP1 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows GDI Elevation of Privilege Vulnerability". T | 1.3% | — |
| CVE-2017-10616 | MED 5.3 | juniper contrail The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected releases are Contrail releases 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prior to 3.1.4.0; 3.2 prior to 3.2.5.0. CVE-2017-10616 and CVE-2017 | 1.3% | — |
| CVE-2012-5128 | HIGH 7.5 | google chrome Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, does not properly perform write operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | 1.3% | — |
| CVE-2010-3718 | LOW 1.2 | apache tomcat Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstra | 1.3% | — |
| CVE-2008-6819 | MED 4.7 | microsoft windows_2003_server win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerabilit | 1.3% | — |