57.872 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.872 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22323 | MED 6.5 | ibm security_verify_password_synchronization IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vu | 1.1% | — |
| CVE-2022-22312 | MED 6.5 | ibm security_verify_password_synchronization IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vu | 1.1% | — |
| CVE-2021-0251 | HIGH 8.6 | juniper junos A NULL Pointer Dereference vulnerability in the Captive Portal Content Delivery (CPCD) services daemon (cpcd) of Juniper Networks Junos OS on MX Series with MS-PIC, MS-SPC3, MS-MIC or MS-MPC allows an attacker to send malformed HTTP packets to the device there | 1.1% | — |
| CVE-2020-17138 | MED 5.5 | microsoft windows_10 Windows Error Reporting Information Disclosure Vulnerability | 1.1% | — |
| CVE-2019-0051 | MED 6.5 | juniper junos SSL-Proxy feature on SRX devices fails to handle a hardware resource limitation which can be exploited by remote SSL/TLS servers to crash the flowd daemon. Repeated crashes of the flowd daemon can result in an extended denial of service condition. For this iss | 1.1% | — |
| CVE-2013-1294 | HIGH 7.0 | microsoft windows_7 Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges | 1.1% | — |
| CVE-2011-4742 | MED 5.0 | parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive informa | 1.1% | — |
| CVE-2011-4741 | MED 5.0 | parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a database connection string within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by client@2/domain@1/ho | 1.1% | — |
| CVE-2011-4737 | MED 5.0 | parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by password handling in clien | 1.1% | — |
| CVE-2011-4736 | MED 5.0 | parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 receives cleartext password input over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by forms in login_up.php3 and certain other | 1.1% | — |
| CVE-2011-4729 | MED 5.0 | parallels parallels_plesk_panel The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access | 1.1% | — |
| CVE-2011-4728 | MED 5.0 | parallels parallels_plesk_panel The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http | 1.1% | — |
| CVE-2010-2821 | HIGH 7.1 | cisco firewall_services_module Unspecified vulnerability on the Cisco Firewall Services Module (FWSM) with software 3.2 before 3.2(17.2), 4.0 before 4.0(11.1), and 4.1 before 4.1(1.2) for Catalyst 6500 series switches and 7600 series routers, when multi-mode is enabled, allows remote attack | 1.1% | — |
| CVE-2023-20252 | CRIT 9.8 | cisco catalyst_sd-wan_manager A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user. This vulnerability is due to | 1.1% | — |
| CVE-2020-17521 | MED 5.5 | apache atlas Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems | 1.1% | — |
| CVE-2019-1571 | MED 4.8 | paloaltonetworks expedition The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings. | 1.1% | — |
| CVE-2019-1570 | MED 4.8 | paloaltonetworks expedition The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings. | 1.1% | — |
| CVE-2019-1569 | MED 4.8 | paloaltonetworks expedition The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user. | 1.1% | — |
| CVE-2024-49090 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-38190 | HIGH 8.6 | microsoft power_platform Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector. | 1.1% | — |
| CVE-2024-32115 | MED 5.5 | fortinet fortimanager A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests. | 1.1% | — |
| CVE-2024-20738 | CRIT 9.8 | adobe framemaker_publishing_server Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain u | 1.1% | — |
| CVE-2023-38140 | MED 5.5 | microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability | 1.1% | — |
| CVE-2022-41044 | HIGH 8.1 | microsoft windows_7 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2020-5933 | HIGH 7.5 | f5 big-ip_access_policy_manager On versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, when a BIG-IP system that has a virtual server configured with an HTTP compression profile processes compressed HTTP message payloads that require deflation, a | 1.1% | — |