57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-12322 | MED 6.1 | cisco email_encryption Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an undes | 0.9% | — |
| CVE-2017-12321 | MED 6.1 | cisco registered_envelope_service Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an undes | 0.9% | — |
| CVE-2017-12320 | MED 6.1 | cisco registered_envelope_service Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an undes | 0.9% | — |
| CVE-2017-12292 | MED 6.1 | cisco email_encryption Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an undes | 0.9% | — |
| CVE-2017-12291 | MED 6.1 | cisco email_encryption Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an undes | 0.9% | — |
| CVE-2017-12290 | MED 6.1 | cisco email_encryption Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an undes | 0.9% | — |
| CVE-2017-12257 | MED 6.1 | cisco webex_meetings_server A vulnerability in the web framework of Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficie | 0.9% | — |
| CVE-2017-12220 | MED 6.1 | cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affec | 0.9% | — |
| CVE-2013-4669 | MED 5.4 | fortinet forticlient FortiClient before 4.3.5.472 on Windows, before 4.0.3.134 on Mac OS X, and before 4.0 on Android; FortiClient Lite before 4.3.4.461 on Windows; FortiClient Lite 2.0 through 2.0.0223 on Android; and FortiClient SSL VPN before 4.0.2258 on Linux proceed with an S | 0.9% | — |
| CVE-2010-4158 | LOW 2.1 | fedoraproject fedora The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instruction, which allows local users to obtain p | 0.9% | — |
| CVE-2026-61918 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-47285 | MED 6.5 | microsoft visual_studio_code Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-20824 | MED 5.5 | microsoft windows_10_1607 Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally. | 0.9% | — |
| CVE-2025-47955 | HIGH 7.8 | microsoft windows_10_1507 Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 0.9% | — |
| CVE-2024-50083 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: fix mptcp DSS corruption due to large pmtu xmit Syzkaller was able to trigger a DSS corruption: TCP: request_sock_subflow_v4: Possible SYN flooding on port [::]:20002. Sending cookie | 0.9% | — |
| CVE-2024-28897 | MED 6.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2024-24275 | CRIT 9.6 | teamwire teamwire Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function. | 0.9% | — |
| CVE-2021-38637 | MED 5.5 | microsoft windows_10 Windows Storage Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-38636 | MED 5.5 | microsoft windows_10 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-38635 | MED 5.5 | microsoft windows_10 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-36972 | MED 5.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-36969 | MED 5.5 | microsoft windows_10 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-31356 | HIGH 7.8 | juniper junos_os_evolved A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the curre | 0.9% | — |
| CVE-2020-3154 | MED 4.9 | cisco cloud_web_security A vulnerability in the web UI of Cisco Cloud Web Security (CWS) could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web-based management interface improperly validates SQL values. An authenticate | 0.9% | — |
| CVE-2020-0644 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Microsoft Windows implements predictable memory section names, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0635. | 0.9% | — |