CVE Tracker
Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.
1,540
Total CVEs
1,540
CISA KEV
1540
Critical & High
Mar 11, 2026
Last KEV Update
| CVE ID | Severity | Vendor | Description | Published | KEV |
|---|---|---|---|---|---|
| CVE-2018-1273 | High | VMware TanzuSpring Data Commons | Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution. | Mar 25, 2022 | KEV |
| CVE-2018-11138 | High | QuestKACE System Management Appliance | The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution. | Mar 25, 2022 | KEV |
| CVE-2018-0147 | High | CiscoSecure Access Control System (ACS) | A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. | Mar 25, 2022 | KEV |
| CVE-2018-0125 | High | CiscoVPN Routers | A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system. | Mar 25, 2022 | KEV |
| CVE-2017-6334 | High | NETGEARDGN2200 Devices | dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands | Mar 25, 2022 | KEV |
| CVE-2019-2616 | High | OracleBI Publisher (Formerly XML Publisher) | Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass. | Mar 25, 2022 | KEV |
| CVE-2019-16920 | High | D-LinkMultiple Routers | Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise. | Mar 25, 2022 | KEV |
| CVE-2019-15107 | High | WebminWebmin | An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability. | Mar 25, 2022 | KEV |
| CVE-2017-6316 | High | CitrixNetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server | A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server. | Mar 25, 2022 | KEV |
| CVE-2017-12617 | High | ApacheTomcat | When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. | Mar 25, 2022 | KEV |
| CVE-2017-12615 | High | ApacheTomcat | When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. | Mar 25, 2022 | KEV |
| CVE-2017-0146 | High | MicrosoftWindows | The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution. | Mar 25, 2022 | KEV |
| CVE-2016-7892 | High | AdobeFlash Player | Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class. | Mar 25, 2022 | KEV |
| CVE-2017-3881 | High | CiscoIOS and IOS XE | A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. | Mar 25, 2022 | KEV |
| CVE-2016-4171 | High | AdobeFlash Player | Unspecified vulnerability in Adobe Flash Player allows for remote code execution. | Mar 25, 2022 | KEV |
| CVE-2016-1555 | High | NETGEARWireless Access Point (WAP) Devices | Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution. | Mar 25, 2022 | KEV |
| CVE-2016-10174 | High | NETGEARWNR2000v5 Router | The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution. | Mar 25, 2022 | KEV |
| CVE-2015-3035 | High | TP-LinkMultiple Archer Devices | Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/. | Mar 25, 2022 | KEV |
| CVE-2015-1187 | High | D-Link and TRENDnetMultiple Devices | The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution. | Mar 25, 2022 | KEV |
| CVE-2015-0666 | High | CiscoPrime Data Center Network Manager (DCNM) | Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files. | Mar 25, 2022 | KEV |