57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-32033 | MED 6.6 | microsoft windows_server_2008 Microsoft Failover Cluster Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-20768 | MED 4.9 | cisco telepresence_collaboration_endpoint A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to the sto | 0.9% | — |
| CVE-2021-39086 | MED 5.3 | ibm sterling_file_gateway IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be | 0.9% | — |
| CVE-2021-34509 | MED 5.5 | microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability | 0.9% | — |
| CVE-2020-1609 | HIGH 8.8 | juniper junos When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv6 packets who may then arbitrarily execute comma | 0.9% | — |
| CVE-2018-0393 | MED 6.5 | cisco mobility_services_engine_3310_firmware A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to make policy changes in the Policy Builder interface. The vulnerability is due to insufficient authorization cont | 0.9% | — |
| CVE-2015-0687 | MED 6.3 | cisco ios The SNMP implementation in Cisco IOS 15.1(2)SG4 on Catalyst 4500 devices, when single-switch Virtual Switching System (VSS) is configured, allows remote authenticated users to cause a denial of service (device crash) by performing SNMP polling, aka Bug ID CSCu | 0.9% | — |
| CVE-2014-8372 | MED 4.0 | vmware airwatch AirWatch by VMware On-Premise 7.3.x before 7.3.3.0 (FP3) allows remote authenticated users to obtain the organizational information and statistics from arbitrary tenants via vectors involving a direct object reference. | 0.9% | — |
| CVE-2013-6692 | MED 6.3 | cisco ios_xe Cisco IOS XE 3.8S(.2) and earlier does not properly use a DHCP pool during assignment of an IP address, which allows remote authenticated users to cause a denial of service (device reload) via an AAA packet that triggers an address requirement, aka Bug ID CSCu | 0.9% | — |
| CVE-2013-1139 | MED 4.0 | cisco cloud_portal The nsAPI interface in Cisco Cloud Portal 9.1 SP1 and SP2, and 9.3 through 9.3.2, does not properly check privileges, which allows remote authenticated users to obtain sensitive information via a crafted URL, aka Bug ID CSCud81134. | 0.9% | — |
| CVE-2012-3895 | MED 6.3 | cisco ios Cisco IOS 15.0 through 15.3 allows remote authenticated users to cause a denial of service (device crash) via an MVPNv6 update, aka Bug ID CSCty89224. | 0.9% | — |
| CVE-2010-4604 | HIGH 7.2 | ibm tivoli_storage_manager Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.2.10, and 6.1.x | 0.9% | — |
| CVE-2026-50649 | HIGH 7.8 | microsoft .net Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. | 0.9% | — |
| CVE-2026-27651 | HIGH 7.5 | f5 nginx_open_source When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server p | 0.9% | — |
| CVE-2026-21229 | HIGH 8.0 | microsoft power_bi_report_server Improper input validation in Power BI allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2024-43495 | HIGH 7.3 | microsoft windows_11_22h2 Windows libarchive Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-36562 | HIGH 7.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-36410 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2023-36031 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2023-27559 | MED 5.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash when using a specially crafted subquery. IBM X-Force ID: 249196. | 0.9% | — |
| CVE-2022-23678 | MED 5.9 | hp aruba_virtual_intranet_access A vulnerability in the Aruba Virtual Intranet Access (VIA) client for Microsoft Windows operating system client communications that could allow for an attacker in a privileged network position to intercept sensitive information in Aruba Virtual Intranet Access | 0.9% | — |
| CVE-2022-0805 | HIGH 8.8 | google chrome Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction. | 0.9% | — |
| CVE-2022-0791 | HIGH 8.8 | google chrome Use after free in Omnibox in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via user interactions. | 0.9% | — |
| CVE-2021-21993 | MED 6.5 | vmware cloud_foundation The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library. An authorised user with access to content library may exploit this issue by sending a POST request to vCenter | 0.9% | — |
| CVE-2020-2003 | MED 6.5 | paloaltonetworks pan-os An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system files affecting the integrity of the system or causing denial of service to all PAN-OS services. This issue affec | 0.9% | — |