57.613 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.613 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-3860 | HIGH 8.6 | cisco ios Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a | 2.8% | — |
| CVE-2017-3846 | HIGH 8.6 | cisco tidal_enterprise_scheduler A vulnerability in the Client Manager Server of Cisco Workload Automation and Cisco Tidal Enterprise Scheduler could allow an unauthenticated, remote attacker to retrieve any file from the Client Manager Server. The vulnerability is due to insufficient input v | 2.0% | — |
| CVE-2017-3790 | HIGH 8.6 | cisco expressway A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software could allow an unauthenticated, remote attacker to cause a reload of the affected system, resulting in a denial of service | 3.5% | — |
| CVE-2017-2321 | HIGH 8.6 | juniper northstar_controller A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modification of | 1.5% | — |
| CVE-2017-2317 | HIGH 8.6 | juniper northstar_controller A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading t | 0.9% | — |
| CVE-2017-12293 | HIGH 8.6 | cisco webex_meetings_server A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient limitations on the number of connections that can be made to the affected soft | 2.3% | — |
| CVE-2017-12246 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service | 6.5% | — |
| CVE-2017-12245 | HIGH 8.6 | cisco secure_firewall_management_center A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause depletion of system memory, aka a Firepower Detection Engine SSL Decryption Memory Consumption Denial of Servic | 1.6% | — |
| CVE-2017-12244 | HIGH 8.6 | cisco secure_firewall_management_center A vulnerability in the detection engine parsing of IPv6 packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause high CPU utilization or to cause a denial of service (DoS) condition because the Snort process restarts | 1.6% | — |
| CVE-2017-10605 | HIGH 8.6 | juniper junos On all vSRX and SRX Series devices, when the DHCP or DHCP relay is configured, specially crafted packet might cause the flowd process to crash, halting or interrupting traffic from flowing through the device(s). Repeated crashes of the flowd process may consti | 1.6% | — |
| CVE-2016-9225 | HIGH 8.6 | cisco asa_cx_context-aware_security_software A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an unauthenticated, remote attacker to cause the CX module to be unable to process further traffic, resulting in a | 2.7% | — |
| CVE-2016-6368 | HIGH 8.6 | cisco secure_firewall_management_center A vulnerability in the detection engine parsing of Pragmatic General Multicast (PGM) protocol packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unex | 3.0% | — |
| CVE-2016-1394 | HIGH 8.6 | cisco firesight_system_software Cisco Firepower System Software 6.0.0 through 6.1.0 has a hardcoded account, which allows remote attackers to obtain CLI access by leveraging knowledge of the password, aka Bug ID CSCuz56238. | 1.0% | — |
| CVE-2016-1373 | HIGH 8.6 | cisco finesse The gadgets-integration API in Cisco Finesse 8.5(1) through 8.5(5), 8.6(1), 9.0(1), 9.0(2), 9.1(1), 9.1(1)SU1, 9.1(1)SU1.1, 9.1(1)ES1 through 9.1(1)ES5, 10.0(1), 10.0(1)SU1, 10.0(1)SU1.1, 10.5(1), 10.5(1)ES1 through 10.5(1)ES4, 10.5(1)SU1, 10.5(1)SU1.1, 10.5(1 | 1.1% | — |
| CVE-2016-1286 | HIGH 8.6 | canonical ubuntu_linux named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c. | 62.1% | — |
| CVE-2015-8555 | HIGH 8.6 | citrix xenserver Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspec | 2.3% | — |
| CVE-2015-5259 | HIGH 8.6 | apache subversion Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of-bounds re | 57.0% | — |
| CVE-2026-70178 | HIGH 8.5 | microsoft fabric Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-69857 | HIGH 8.5 | microsoft azure_cosmos_db Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network. | 0.4% | — |
| CVE-2026-69543 | HIGH 8.5 | microsoft azure_virtual_machines Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network. | 0.3% | — |
| CVE-2026-69419 | HIGH 8.5 | microsoft azure_data_manager_for_energy Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. | 0.4% | — |
| CVE-2026-67636 | HIGH 8.5 | microsoft sql_server_2019 Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network. | — | — |
| CVE-2026-65818 | HIGH 8.5 | microsoft power_platform Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. | 0.3% | — |
| CVE-2026-65092 | HIGH 8.5 | nvidia openshell NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering. | 0.5% | — |
| CVE-2026-56167 | HIGH 8.5 | microsoft azure_ai_search Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. | 0.4% | — |