IT
58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.046 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2019-1569 MED 4.8 paloaltonetworks expedition The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user. 1.1%
CVE-2026-69525 CRIT 9.8 microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. 1.1%
CVE-2026-26154 HIGH 7.5 microsoft windows_server_2012 Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. 1.1%
CVE-2024-49997 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix memory disclosure When applying padding, the buffer is not zeroed, which results in memory disclosure. The mentioned data is observed on the wire. This patch 1.1%
CVE-2023-50379 HIGH 8.8 apache ambari Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster 1.1%
CVE-2022-22323 MED 6.5 ibm security_verify_password_synchronization IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vu 1.1%
CVE-2022-22312 MED 6.5 ibm security_verify_password_synchronization IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vu 1.1%
CVE-2021-0251 HIGH 8.6 juniper junos A NULL Pointer Dereference vulnerability in the Captive Portal Content Delivery (CPCD) services daemon (cpcd) of Juniper Networks Junos OS on MX Series with MS-PIC, MS-SPC3, MS-MIC or MS-MPC allows an attacker to send malformed HTTP packets to the device there 1.1%
CVE-2020-17138 MED 5.5 microsoft windows_10 Windows Error Reporting Information Disclosure Vulnerability 1.1%
CVE-2019-0051 MED 6.5 juniper junos SSL-Proxy feature on SRX devices fails to handle a hardware resource limitation which can be exploited by remote SSL/TLS servers to crash the flowd daemon. Repeated crashes of the flowd daemon can result in an extended denial of service condition. For this iss 1.1%
CVE-2013-1294 HIGH 7.0 microsoft windows_7 Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges 1.1%
CVE-2011-4742 MED 5.0 parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive informa 1.1%
CVE-2011-4741 MED 5.0 parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a database connection string within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by client@2/domain@1/ho 1.1%
CVE-2011-4737 MED 5.0 parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by password handling in clien 1.1%
CVE-2011-4736 MED 5.0 parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 receives cleartext password input over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by forms in login_up.php3 and certain other 1.1%
CVE-2011-4729 MED 5.0 parallels parallels_plesk_panel The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access 1.1%
CVE-2011-4728 MED 5.0 parallels parallels_plesk_panel The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http 1.1%
CVE-2010-2821 HIGH 7.1 cisco firewall_services_module Unspecified vulnerability on the Cisco Firewall Services Module (FWSM) with software 3.2 before 3.2(17.2), 4.0 before 4.0(11.1), and 4.1 before 4.1(1.2) for Catalyst 6500 series switches and 7600 series routers, when multi-mode is enabled, allows remote attack 1.1%
CVE-2025-29801 HIGH 7.8 microsoft autoupdate Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. 1.1%
CVE-2025-29800 HIGH 7.8 microsoft autoupdate Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. 1.1%
CVE-2024-32638 MED 6.3 apache apisix Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0. Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, wh 1.1%
CVE-2022-20913 MED 4.9 cisco nexus_dashboard A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to insufficient input validation in the web-based management interface of Cisco Nexus Dashboard. An 1.1%
CVE-2021-31954 HIGH 7.8 microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability 1.1%
CVE-2017-7217 MED 4.3 paloaltonetworks pan-os The Management Web Interface in Palo Alto Networks PAN-OS before 7.0.14 and 7.1.x before 7.1.9 allows remote attackers to write to export files via unspecified parameters. 1.1%
CVE-2017-6141 MED 5.9 f5 big-ip_access_policy_manager In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, and WebSafe 12.1.0 through 12.1.2, certain values in a TLS abbreviated handshake when using a client SSL profile with the Session Ticket option enabled may cause disruption of service to the Traffic M 1.1%