57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.808 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-20355 | MED 5.3 | ibm jazz_team_server IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from th | 1.1% | — |
| CVE-2020-3448 | MED 5.8 | cisco cyber_vision_center A vulnerability in an access control mechanism of Cisco Cyber Vision Center Software could allow an unauthenticated, remote attacker to bypass authentication and access internal services that are running on an affected device. The vulnerability is due to insuf | 1.1% | — |
| CVE-2019-15255 | MED 6.5 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the sof | 1.1% | — |
| CVE-2010-4487 | HIGH 7.5 | google chrome Incomplete blacklist vulnerability in Google Chrome before 8.0.552.215 on Linux and Mac OS X allows remote attackers to have an unspecified impact via a "dangerous file." | 1.1% | — |
| CVE-2023-22946 | MED 6.4 | apache spark In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application can execute code with the privileges of the submitting user, however, by providing malicious configuration-relat | 1.1% | — |
| CVE-2022-41039 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2019-12644 | MED 6.1 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an aff | 1.1% | — |
| CVE-2016-7561 | HIGH 7.2 | fortinet fortiwlc Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 allow administrators to obtain sensitive user credentials by reading the pam.log file. | 1.1% | — |
| CVE-2014-3335 | MED 4.6 | cisco asr_9000_rsp440_router Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicast destination MAC addresses, which allows remote attackers to cause a denial of service (chip and card hangs) via a crafted packet, aka Bug | 1.1% | — |
| CVE-1999-0445 | MED 5.0 | cisco ios In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters. | 1.1% | — |
| CVE-2025-21366 | HIGH 7.8 | microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-41032 | HIGH 7.8 | fedoraproject fedora NuGet Client Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2018-0977 | HIGH 7.0 | microsoft windows_10 The Windows kernel mode driver in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how objects are handled in memory, aka "Win32k Elevation of Privilege Vuln | 1.1% | — |
| CVE-2018-0881 | HIGH 7.0 | microsoft windows_10 The Microsoft Video Control in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of pri | 1.1% | — |
| CVE-2007-6193 | MED 5.0 | citrix netscaler The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attackers to obtain sensitive network configuration information if this address is not the same as the address being us | 1.1% | — |
| CVE-2026-42253 | MED 6.1 | apache activemq Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The MessageServlet in the ActiveMQ web console API copies every JMS message property into an HTTP response header witho | 1.1% | — |
| CVE-2025-21413 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2025-21411 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2025-21409 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2025-21339 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-0135 | HIGH 7.6 | nvidia nvidia_container_toolkit NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of | 1.1% | — |
| CVE-2023-36047 | HIGH 7.8 | microsoft windows_10_1809 Windows Authentication Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-22130 | MED 6.7 | fortinet fortiproxy A stack-based buffer overflow vulnerability in FortiProxy physical appliance CLI 2.0.0 to 2.0.1, 1.2.0 to 1.2.9, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 may allow an authenticated, remote attacker to perform a Denial of Service attack by running the `diagnose sys cpuse | 1.1% | — |
| CVE-2020-1656 | HIGH 8.8 | juniper junos The DHCPv6 Relay-Agent service, part of the Juniper Enhanced jdhcpd daemon shipped with Juniper Networks Junos OS has an Improper Input Validation vulnerability which will result in a Denial of Service (DoS) condition when a DHCPv6 client sends a specific DHPC | 1.1% | — |
| CVE-2019-5517 | MED 6.8 | vmware esxi VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) contain multiple out-of-bounds read vulnerabilities in the shader transl | 1.1% | — |