57.977 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.977 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-43496 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2020-3244 | MED 5.3 | cisco staros A vulnerability in the Enhanced Charging Service (ECS) functionality of Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass the traffic classification rules on an affected device. The vulnerability is du | 1.0% | — |
| CVE-2020-12393 | HIGH 7.8 | mozilla firefox The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in comman | 1.0% | — |
| CVE-2019-2390 | HIGH 8.2 | mongodb mongodb An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs shipped with MongoDB server to run attacker defined code as the user running the utility. This issue MongoDB Server | 1.0% | — |
| CVE-2019-15988 | MED 5.3 | cisco email_security_appliance_firmware A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to ins | 1.0% | — |
| CVE-2017-8702 | HIGH 7.0 | microsoft windows_10 Windows Error Reporting (WER) in Microsoft Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows an attacker to gain greater access to sensitive information and system functionality, due to the way that WER handles and executes files, aka "Windows El | 1.0% | — |
| CVE-2015-4077 | LOW 2.1 | fortinet forticlient The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to read arbitrary kernel memory via a 0x22608C ioctl call. | 1.0% | — |
| CVE-2006-3593 | MED 4.0 | cisco unified_callmanager The command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to overwrite arbitrary files by redirecting a command's output to a file or folder, aka bug CSCse31704. | 1.0% | — |
| CVE-2023-51785 | HIGH 7.5 | apache inlong Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack using mysql driver. Users are advised to upgrade to Apache InLong's 1.10.0 or cherr | 1.0% | — |
| CVE-2023-21776 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 1.0% | — |
| CVE-2022-26935 | MED 6.5 | microsoft windows_10 Windows WLAN AutoConfig Service Information Disclosure Vulnerability | 1.0% | — |
| CVE-2022-22310 | MED 6.5 | ibm websphere_application_server IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to JAX-WS applications. IBM X-Force ID: | 1.0% | — |
| CVE-2022-20752 | MED 5.3 | cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This | 1.0% | — |
| CVE-2020-5406 | MED 6.5 | vmware tanzu_application_service_for_vms VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection properties to its log, including database usernam | 1.0% | — |
| CVE-2020-26072 | HIGH 8.7 | cisco iot_field_network_director A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the | 1.0% | — |
| CVE-2018-0390 | MED 6.1 | cisco webex_meetings A vulnerability in the web framework of Cisco Webex could allow an unauthenticated, remote attacker to conduct a Document Object Model-based (DOM-based) cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerab | 1.0% | — |
| CVE-2017-8577 | HIGH 7.0 | microsoft windows_10 Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to | 1.0% | — |
| CVE-2016-1394 | HIGH 8.6 | cisco firesight_system_software Cisco Firepower System Software 6.0.0 through 6.1.0 has a hardcoded account, which allows remote attackers to obtain CLI access by leveraging knowledge of the password, aka Bug ID CSCuz56238. | 1.0% | — |
| CVE-2023-38188 | MED 4.5 | microsoft azure_hdinsight Azure Apache Hadoop Spoofing Vulnerability | 1.0% | — |
| CVE-2022-35715 | HIGH 7.5 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 231 | 1.0% | — |
| CVE-2022-20958 | HIGH 8.3 | cisco broadworks_commpilot_application A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to insuff | 1.0% | — |
| CVE-2021-31167 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-22985 | HIGH 7.5 | f5 big-ip_application_security_manager On BIG-IP APM version 16.0.x before 16.0.1.1, under certain conditions, when processing VPN traffic with APM, TMM consumes excessive memory. A malicious, authenticated VPN user may abuse this to perform a DoS attack against the APM. Note: Software versions whi | 1.0% | — |
| CVE-2020-0843 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins | 1.0% | — |
| CVE-2020-0842 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins | 1.0% | — |