58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.046 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-2331 | HIGH 7.3 | juniper northstar_controller A firewall bypass vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to bypass firewall policies, leading to authentication bypass methods, information disclosur | 1.1% | — |
| CVE-2015-0709 | MED 6.8 | cisco ios Cisco IOS 15.5S and IOS XE allow remote authenticated users to cause a denial of service (device crash) by leveraging knowledge of the RADIUS secret and sending crafted RADIUS packets, aka Bug ID CSCur21348. | 1.1% | — |
| CVE-2022-38020 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-26865 | HIGH 8.8 | microsoft windows_10 Windows Container Execution Agent Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2020-3121 | MED 6.1 | cisco sf350-48_firmware A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to | 1.1% | — |
| CVE-2019-16018 | MED 6.5 | cisco ios_xr A vulnerability in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrec | 1.1% | — |
| CVE-2023-23374 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-1534 | MED 5.8 | cisco asyncos A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to im | 1.1% | — |
| CVE-2019-1856 | MED 6.1 | cisco prime_collaboration_assurance A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance (PCA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affecte | 1.1% | — |
| CVE-2017-2319 | HIGH 8.3 | juniper northstar_controller A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker to compromise the systems confidentiality or integrity without authentication, leading to managed systems being compromise | 1.1% | — |
| CVE-2024-50566 | HIGH 7.2 | fortinet fortimanager A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 through 7.4.4, FortiManager Cloud 7.2.2 through 7.2.7, FortiManager 7.6.0 th | 1.1% | — |
| CVE-2023-41678 | HIGH 8.8 | fortinet fortios A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request. | 1.1% | — |
| CVE-2021-40129 | MED 4.9 | cisco common_services_platform_collector A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to submit a SQL query through the CSPC configuration dashboard. This vulnerability is due to insufficient input vali | 1.1% | — |
| CVE-2021-36930 | MED 5.3 | microsoft edge Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2019-1578 | MED 6.1 | paloaltonetworks minemeld Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker able to convince an authenticated MineMeld admin to type malicious input in the MineMeld UI could execute arbitrary JavaScript code in the | 1.1% | — |
| CVE-2018-4414 | HIGH 7.8 | apple icloud A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7. | 1.1% | — |
| CVE-2012-5044 | MED 5.4 | cisco ios Cisco IOS before 15.3(1)T, when media flow-around is not used, allows remote attackers to cause a denial of service (media loops and stack memory corruption) via VoIP traffic, aka Bug ID CSCub45809. | 1.1% | — |
| CVE-2012-1317 | MED 5.4 | cisco ios The multicast implementation in Cisco IOS before 15.1(1)SY allows remote attackers to cause a denial of service (Route Processor crash) by sending packets at a high rate, aka Bug ID CSCts37717. | 1.1% | — |
| CVE-2026-50429 | HIGH 8.2 | microsoft windows_10_1607 Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2024-43566 | HIGH 7.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-36007 | HIGH 7.6 | microsoft send_customer_voice_survey_from_dynamics_365 Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability | 1.1% | — |
| CVE-2023-28350 | MED 6.1 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console applications, enabling an attacker to execute JavaScript in these applications. | 1.1% | — |
| CVE-2021-1620 | HIGH 7.7 | cisco ios A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to exhaust the free IP addresses from the assigned local pool. Th | 1.1% | — |
| CVE-2021-1470 | MED 4.9 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper input validation of SQL que | 1.1% | — |
| CVE-2019-1954 | MED 6.1 | cisco webex_meetings_server A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL paramete | 1.1% | — |