57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2024-20358 | MED 6.0 | cisco adaptive_security_appliance_software A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the und | 0.7% | — |
| CVE-2024-20357 | MED 5.9 | cisco ip_phone_6821_with_multiplatform_firmware A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device. This vulnerability exists because bounds-checking does not occur while parsing XML requests. An at | 0.5% | — |
| CVE-2024-20355 | MED 5.0 | cisco adaptive_security_appliance_software A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to success | 0.3% | — |
| CVE-2024-20354 | MED 4.7 | cisco ios_xe A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to inco | 0.3% | — |
| CVE-2024-20352 | MED 4.9 | cisco emergency_responder A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient pro | 1.5% | — |
| CVE-2024-20351 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firepower Threat Defense (FTD) Software and Cisco FirePOWER Services could allow an unauthenticated, remote attacker to cause legitimate network traffic to be droppe | 0.7% | — |
| CVE-2024-20350 | HIGH 7.5 | cisco catalyst_center A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appliance. This vulnerability is due to the presence of a static SSH host key. An a | 0.4% | — |
| CVE-2024-20348 | HIGH 7.5 | cisco nexus_dashboard_fabric_controller A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This vulnerability is due to an unauthenticated provisioning web | 0.8% | — |
| CVE-2024-20347 | MED 4.3 | cisco emergency_responder A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for | 0.2% | — |
| CVE-2024-20346 | MED 5.4 | cisco appdynamics_controller A vulnerability in the web-based management interface of Cisco AppDynamics Controller could allow an authenticated, remote attacker to perform a reflected cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerab | 0.4% | — |
| CVE-2024-20345 | MED 6.5 | cisco appdynamics_controller A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. This vulnerability is due to insufficient validation of user-suppli | 2.2% | — |
| CVE-2024-20344 | MED 5.3 | cisco imm_management_package A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the Device Console UI | 0.8% | — |
| CVE-2024-20343 | MED 5.5 | cisco ios_xr A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of the underlying Linux operating system. The attacker must have valid credentials on the affected device. This vulnerabilit | 0.1% | — |
| CVE-2024-20342 | MED 5.8 | cisco secure_firewall_threat_defense Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured rate limiting filter. This vulnerability is due to an incor | 0.5% | — |
| CVE-2024-20341 | MED 6.1 | cisco adaptive_security_appliance_software A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against | 0.4% | — |
| CVE-2024-20340 | MED 6.5 | cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to perform an SQL injection attack against an affected | 0.5% | — |
| CVE-2024-20339 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in the TLS processing feature of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerabi | 0.7% | — |
| CVE-2024-20338 | HIGH 7.3 | cisco secure_client A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to the use of an uncontrolled search path element. A | 0.9% | — |
| CVE-2024-20337 | HIGH 8.2 | cisco secure_client A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of | 29.9% | — |
| CVE-2024-20336 | MED 6.5 | cisco wap121_firmware A vulnerability in the web-based user interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to perform buffer overflow attacks against an affected device. In order to exploit this vulnerability, t | 0.8% | — |
| CVE-2024-20335 | MED 6.5 | cisco wap121_firmware A vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to perform command injection attacks against an affected device. In order to exploit this vulnerab | 1.0% | — |
| CVE-2024-20334 | MED 5.5 | cisco telepresence_management_suite A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to ins | 0.4% | — |
| CVE-2024-20333 | MED 4.3 | cisco catalyst_center A vulnerability in the web-based management interface of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an authenticated, remote attacker to change specific data within the interface on an affected device. This vulnerability is due to insuffi | 0.4% | — |
| CVE-2024-20332 | MED 5.5 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to impro | 0.4% | — |
| CVE-2024-20331 | MED 6.8 | cisco adaptive_security_appliance_software A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to prevent us | 0.7% | — |