IT
57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2019-1949 MED 4.8 cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. 0.8%
CVE-2019-15268 MED 4.8 cisco amp_7150_firmware Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. These v 0.8%
CVE-2019-12668 MED 4.8 cisco ios A vulnerability in the web framework code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected software using the banner p 0.8%
CVE-2019-12667 MED 4.8 cisco ios_xe A vulnerability in the web framework code of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected software. The vulnerability is due to ins 0.8%
CVE-2019-12626 MED 4.8 cisco unified_contact_center_express A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface 0.8%
CVE-2017-7666 HIGH 8.8 apache openmeetings Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks. 0.8%
CVE-2017-6602 MED 4.4 cisco firepower_extensible_operating_system A vulnerability in the CLI of Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection att 0.8%
CVE-2025-29825 MED 6.5 microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.8%
CVE-2024-42004 HIGH 7.1 microsoft teams A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and 0.8%
CVE-2024-24860 MED 4.6 linux linux_kernel A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue. 0.8%
CVE-2024-20254 CRIT 9.6 cisco expressway Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected devic 0.8%
CVE-2023-35373 MED 5.3 microsoft mono Mono Authenticode Validation Spoofing Vulnerability 0.8%
CVE-2022-29134 MED 6.5 microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability 0.8%
CVE-2022-29127 MED 4.2 microsoft windows_10 BitLocker Security Feature Bypass Vulnerability 0.8%
CVE-2022-29123 MED 6.5 microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability 0.8%
CVE-2022-29122 MED 6.5 microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability 0.8%
CVE-2022-26930 MED 5.5 microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.8%
CVE-2022-22011 MED 5.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 0.8%
CVE-2021-28972 MED 6.7 fedoraproject fedora In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame 0.8%
CVE-2021-1440 MED 6.8 cisco ios_xr A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Border Gateway Protocol (BGP) process to crash, resulting in a denial of s 0.8%
CVE-2020-3522 MED 6.3 cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to bypass authorization on an affected device and access sensitive information that is related to the devic 0.8%
CVE-2019-7221 HIGH 7.8 canonical ubuntu_linux The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. 0.8%
CVE-2019-6627 MED 5.9 f5 ssl_orchestrator On F5 SSL Orchestrator 14.1.0-14.1.0.5, on rare occasions, specific to a certain race condition, TMM may restart when SSL Forward Proxy enforces the bypass action for an SSL Orchestrator transparent virtual server with SNAT enabled. 0.8%
CVE-2019-16010 MED 4.8 cisco sd-wan_firmware A vulnerability in the web UI of the Cisco SD-WAN vManage software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the vManage software. The vulnerability is d 0.8%
CVE-2019-1594 HIGH 7.4 cisco nx-os A vulnerability in the 802.1X implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incomplete input validation of Extensible Au 0.8%