58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2021-1151 | MED 4.8 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vu | 0.7% | — |
| CVE-2021-1150 | HIGH 7.2 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilit | 2.4% | — |
| CVE-2021-1149 | HIGH 7.2 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilit | 2.4% | — |
| CVE-2021-1148 | HIGH 7.2 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilit | 2.4% | — |
| CVE-2021-1147 | HIGH 7.2 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilit | 2.4% | — |
| CVE-2021-1146 | HIGH 7.2 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilit | 2.4% | — |
| CVE-2021-1145 | MED 6.5 | cisco staros A vulnerability in the Secure FTP (SFTP) of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an authenticated, remote attacker to read arbitrary files on an affected device. To exploit this vulnerability, the attacker would need to have valid credent | 1.3% | — |
| CVE-2021-1144 | HIGH 8.8 | cisco connected_mobile_experiences A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an affected system. The vulnerability is due to incorrect handling of authorization | 1.4% | — |
| CVE-2021-1143 | MED 4.3 | cisco connected_mobile_experiences A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system. The vulnerability is due to a lack of authorization checks for certain API GET requests. A | 0.7% | — |
| CVE-2021-1142 | CRIT 9.8 | cisco smart_software_manager_satellite Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details | 4.3% | — |
| CVE-2021-1141 | CRIT 9.8 | cisco smart_software_manager_satellite Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details | 4.0% | — |
| CVE-2021-1140 | CRIT 9.8 | cisco smart_software_manager_satellite Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details | 4.4% | — |
| CVE-2021-1139 | CRIT 9.8 | cisco smart_software_manager_satellite Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details | 4.0% | — |
| CVE-2021-1138 | CRIT 9.8 | cisco smart_software_manager_satellite Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details | 4.4% | — |
| CVE-2021-1137 | HIGH 7.8 | cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these v | 0.5% | — |
| CVE-2021-1136 | MED 6.7 | cisco ios_xr Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute u | 0.2% | — |
| CVE-2021-1135 | MED 4.6 | cisco data_center_network_manager Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the | 0.6% | — |
| CVE-2021-1134 | HIGH 7.4 | cisco catalyst_center A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to an incomplete validation | 0.8% | — |
| CVE-2021-1133 | MED 4.6 | cisco data_center_network_manager Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the | 1.1% | — |
| CVE-2021-1132 | MED 5.3 | cisco network_services_orchestrator A vulnerability in the API subsystem and in the web-management interface of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to access sensitive data. This vulnerability exists because the web-management interface | 1.6% | — |
| CVE-2021-1131 | MED 6.5 | cisco video_surveillance_8000p_ip_camera_firmware A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause an affected IP camera to reload. The vulnerability is due to missing checks when Cisco | 0.5% | — |
| CVE-2021-1130 | MED 4.8 | cisco catalyst_center A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists beca | 0.8% | — |
| CVE-2021-1129 | MED 5.3 | cisco content_security_management_appliance A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker | 1.1% | — |
| CVE-2021-1128 | MED 5.5 | cisco ios_xr A vulnerability in the CLI parser of Cisco IOS XR Software could allow an authenticated, local attacker to view more information than their privileges allow. The vulnerability is due to insufficient application of restrictions during the execution of a specifi | 0.3% | — |
| CVE-2021-1127 | MED 5.4 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The | 0.6% | — |