IT
57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2022-21964 MED 5.5 microsoft windows_10 Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability 1.0%
CVE-2021-44230 MED 6.5 portswigger burp_suite PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows accoun 1.0%
CVE-2020-3519 HIGH 8.1 cisco data_center_network_manager A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. The vulnerability is due to insufficient validation of us 1.0%
CVE-2020-3317 HIGH 7.5 cisco secure_firewall_threat_defense A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to crash Snort instances. The vulnerability is due to insufficient input validation in the ssl_inspection component 1.0%
CVE-2023-21778 HIGH 8.0 microsoft dynamics_365 Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability 1.0%
CVE-2022-0806 MED 6.5 google chrome Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page. 1.0%
CVE-2020-4902 HIGH 8.8 ibm datacap_navigator IBM Datacap Taskmaster Capture (IBM Datacap Navigator 9.1.7) is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM 1.0%
CVE-2020-3307 MED 5.3 cisco secure_firewall_management_center A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to write arbitrary entries to the log file on an affected device. The vulnerability is due to insufficient input validation. An at 1.0%
CVE-2017-12227 MED 5.4 cisco emergency_responder A vulnerability in the SQL database interface for Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-supplied input used in SQL queries that by 1.0%
CVE-2016-1470 HIGH 8.8 cisco small_business_220_series_smart_plus_switches Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuz76230. 1.0%
CVE-2013-1406 HIGH 7.2 vmware esx The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows, VMware Fusion 4.1 before 4.1.4 and 5.0 before 5.0.2, VMware View 4.x before 4.6.2 and 5.x before 5.1.2 on Wind 1.0%
CVE-2011-4849 MED 4.3 parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session, as demo 1.0%
CVE-2011-4848 MED 4.3 parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by password handling in certai 1.0%
CVE-2011-4740 MED 4.3 parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates web pages containing external links in response to GET requests with query strings for smb/app/search-data/catalogId/marketplace and certain other files, which makes it easier for re 1.0%
CVE-2011-0217 MED 4.3 apple safari Apple Safari before 5.0.6 provides AutoFill information to scripts that execute before HTML form submission, which allows remote attackers to obtain Address Book information via a crafted form, as demonstrated by a form that includes non-visible fields. 1.0%
CVE-2026-72977 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. 1.0%
CVE-2023-36592 HIGH 7.3 microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2023-36589 HIGH 7.3 microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2023-36575 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2023-36574 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2023-36573 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2023-36572 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2023-36571 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2023-36570 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2021-31850 MED 6.1 mcafee database_security A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator to trigger a denial-of-service attack against the DBS server. The configuration of Archiving through the User interface incorrectly allowed 1.0%