57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-21964 | MED 5.5 | microsoft windows_10 Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability | 1.0% | — |
| CVE-2021-44230 | MED 6.5 | portswigger burp_suite PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows accoun | 1.0% | — |
| CVE-2020-3519 | HIGH 8.1 | cisco data_center_network_manager A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. The vulnerability is due to insufficient validation of us | 1.0% | — |
| CVE-2020-3317 | HIGH 7.5 | cisco secure_firewall_threat_defense A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to crash Snort instances. The vulnerability is due to insufficient input validation in the ssl_inspection component | 1.0% | — |
| CVE-2023-21778 | HIGH 8.0 | microsoft dynamics_365 Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-0806 | MED 6.5 | google chrome Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page. | 1.0% | — |
| CVE-2020-4902 | HIGH 8.8 | ibm datacap_navigator IBM Datacap Taskmaster Capture (IBM Datacap Navigator 9.1.7) is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM | 1.0% | — |
| CVE-2020-3307 | MED 5.3 | cisco secure_firewall_management_center A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to write arbitrary entries to the log file on an affected device. The vulnerability is due to insufficient input validation. An at | 1.0% | — |
| CVE-2017-12227 | MED 5.4 | cisco emergency_responder A vulnerability in the SQL database interface for Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-supplied input used in SQL queries that by | 1.0% | — |
| CVE-2016-1470 | HIGH 8.8 | cisco small_business_220_series_smart_plus_switches Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuz76230. | 1.0% | — |
| CVE-2013-1406 | HIGH 7.2 | vmware esx The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows, VMware Fusion 4.1 before 4.1.4 and 5.0 before 5.0.2, VMware View 4.x before 4.6.2 and 5.x before 5.1.2 on Wind | 1.0% | — |
| CVE-2011-4849 | MED 4.3 | parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session, as demo | 1.0% | — |
| CVE-2011-4848 | MED 4.3 | parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by password handling in certai | 1.0% | — |
| CVE-2011-4740 | MED 4.3 | parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates web pages containing external links in response to GET requests with query strings for smb/app/search-data/catalogId/marketplace and certain other files, which makes it easier for re | 1.0% | — |
| CVE-2011-0217 | MED 4.3 | apple safari Apple Safari before 5.0.6 provides AutoFill information to scripts that execute before HTML form submission, which allows remote attackers to obtain Address Book information via a crafted form, as demonstrated by a form that includes non-visible fields. | 1.0% | — |
| CVE-2026-72977 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2023-36592 | HIGH 7.3 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36589 | HIGH 7.3 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36575 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36574 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36573 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36572 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36571 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36570 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2021-31850 | MED 6.1 | mcafee database_security A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator to trigger a denial-of-service attack against the DBS server. The configuration of Archiving through the User interface incorrectly allowed | 1.0% | — |