58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.046 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-3418 | MED 6.8 | cisco unified_communications_domain_manager Cisco Unified Communications Domain Manager does not properly allocate memory for GET and POST requests, which allows remote authenticated users to cause a denial of service (memory consumption and process crash) via crafted requests to the management interfac | 1.1% | — |
| CVE-2013-1197 | MED 6.8 | cisco unified_presence The XML parser in the server in Cisco Unified Presence (CUP) allows remote authenticated users to cause a denial of service (jabberd daemon crash) via crafted XML content in an XMPP message, aka Bug ID CSCue13912. | 1.1% | — |
| CVE-2009-0742 | HIGH 7.8 | cisco ace_4710 The username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Control Engine Appliance stores a cleartext password by default, which allows context-dependent attackers to obtain s | 1.1% | — |
| CVE-2024-49090 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-38190 | HIGH 8.6 | microsoft power_platform Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector. | 1.1% | — |
| CVE-2024-32115 | MED 5.5 | fortinet fortimanager A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests. | 1.1% | — |
| CVE-2024-20738 | CRIT 9.8 | adobe framemaker_publishing_server Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain u | 1.1% | — |
| CVE-2023-38140 | MED 5.5 | microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability | 1.1% | — |
| CVE-2022-41044 | HIGH 8.1 | microsoft windows_7 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2020-5933 | HIGH 7.5 | f5 big-ip_access_policy_manager On versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, when a BIG-IP system that has a virtual server configured with an HTTP compression profile processes compressed HTTP message payloads that require deflation, a | 1.1% | — |
| CVE-2020-3583 | MED 6.1 | cisco adaptive_security_appliance_software Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a | 1.1% | — |
| CVE-2020-1683 | HIGH 7.5 | juniper junos On Juniper Networks Junos OS devices, a specific SNMP OID poll causes a memory leak which over time leads to a kernel crash (vmcore). Prior to the kernel crash other processes might be impacted, such as failure to establish SSH connection to the device. The ad | 1.1% | — |
| CVE-2020-1632 | HIGH 8.6 | juniper junos In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos OS and Junos OS Evolved devices to advertise an invalid BGP UPDATE message to other peers, causing the other peers to terminate the established BGP session, cre | 1.1% | — |
| CVE-2019-6681 | HIGH 7.5 | f5 big-ip_local_traffic_manager On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, a memory leak in Multicast Forwarding Cache (MFC) handling in tmrouted. | 1.1% | — |
| CVE-2019-6680 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5, while processing traffic through a standard virtual server that targets a FastL4 virtual server (VIP on VIP), hardware appliances may stop respon | 1.1% | — |
| CVE-2019-11751 | HIGH 8.8 | mozilla firefox Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windo | 1.1% | — |
| CVE-2018-8566 | MED 4.6 | microsoft windows_10 A security feature bypass vulnerability exists when Windows improperly suspends BitLocker Device Encryption, aka "BitLocker Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers. | 1.1% | — |
| CVE-2018-6958 | MED 6.1 | vmware vrealize_automation VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to the compromise of the vRA user's workstation. | 1.1% | — |
| CVE-2017-7737 | MED 4.9 | fortinet fortiweb An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code. | 1.1% | — |
| CVE-2017-7337 | CRIT 9.1 | fortinet fortiportal An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to interact with unauthorized VDOMs or enumerate other ADOMs via another user's stolen session and CSRF tokens or the adomName parameter in the /fpc/se | 1.1% | — |
| CVE-2017-6167 | HIGH 7.5 | f5 big-ip_access_policy_manager In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, race conditions in iControl REST may lead to commands being executed with different privilege levels than expected. | 1.1% | — |
| CVE-2023-20252 | CRIT 9.8 | cisco catalyst_sd-wan_manager A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user. This vulnerability is due to | 1.1% | — |
| CVE-2020-17521 | MED 5.5 | apache atlas Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems | 1.1% | — |
| CVE-2019-1571 | MED 4.8 | paloaltonetworks expedition The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings. | 1.1% | — |
| CVE-2019-1570 | MED 4.8 | paloaltonetworks expedition The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings. | 1.1% | — |