IT
58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.046 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2022-46870 MED 5.4 apache zeppelin An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2. Users are 1.1%
CVE-2021-22984 MED 6.1 f5 big-ip_advanced_web_application_firewall On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x before 13.1.3.4, 12.1.x before 12.1.5.2, and 11.6.x before 11.6.5.2, when receiving a unauthenticated client request with a maliciously crafte 1.1%
CVE-2020-16943 MED 6.5 microsoft dynamics_365 <p>An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Commerce. An unauthenticated attacker who successfully exploited this vulnerability could update data without proper authorization.</p> <p>To exploit the vulnerability, an attacker wou 1.1%
CVE-2019-16150 MED 5.5 fortinet forticlient Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configuration backup file to decrypt the sensiti 1.1%
CVE-2003-1569 MED 5.0 goahead goahead_webserver GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-200 1.1%
CVE-2022-41742 HIGH 7.1 debian debian_linux NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to ca 1.1%
CVE-2021-41014 HIGH 7.5 fortinet fortiweb A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets 1.1%
CVE-2020-3973 HIGH 8.8 arista velocloud_orchestrator The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged. 1.1%
CVE-2017-6158 MED 6.5 f5 big-ip_access_policy_manager In F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.1, 11.5.1-11.5.5, or 11.2.1 there is a vulnerability in TMM related to handling of invalid IP addresses. 1.1%
CVE-2012-4116 MED 4.3 cisco unified_computing_system The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allows remote attackers to obtain sensitive information, and consequently complete the authentication process for a server connection, by sniffi 1.1%
CVE-2025-25002 MED 6.8 microsoft azure_local_cluster Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network. 1.1%
CVE-2024-48890 MED 6.6 fortinet fortisoar_imap_connector An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specific 1.1%
CVE-2024-26177 MED 5.5 microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability 1.1%
CVE-2022-33674 HIGH 8.3 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 1.1%
CVE-2021-42301 LOW 3.3 microsoft azure_rtos Azure RTOS Information Disclosure Vulnerability 1.1%
CVE-2020-29661 HIGH 7.8 broadcom fabric_operating_system A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b. 1.1%
CVE-2018-15390 MED 6.8 cisco secure_firewall_threat_defense A vulnerability in the FTP inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists beca 1.1%
CVE-2016-6363 MED 6.5 cisco aironet_access_point_software The rate-limit feature in the 802.11 protocol implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device reload) via crafted 802.11 frames, 1.1%
CVE-2016-6361 MED 6.5 cisco aironet_access_point_software The Aggregated MAC Protocol Data Unit (AMPDU) implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device reload) via a crafted AMPDU header 1.1%
CVE-2016-1441 HIGH 8.2 cisco cloud_network_automation_provisioner Cisco Cloud Network Automation Provisioner (CNAP) 1.0(0) in Cisco Configuration Assistant (CCA) allows remote attackers to bypass intended filesystem and administrative-endpoint restrictions via GET API calls, aka Bug ID CSCuy77145. 1.1%
CVE-2024-38051 HIGH 7.8 microsoft windows_10_1507 Windows Graphics Component Remote Code Execution Vulnerability 1.1%
CVE-2023-36027 HIGH 7.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.1%
CVE-2022-45064 HIGH 8.0 apache apache_sling_engine The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level. The vulnerability is exploitable by an attacker that is able to include a resou 1.1%
CVE-2022-21155 HIGH 7.5 fernhillsoftware scada_server A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing the server process (FHSvrService.exe) to exit. 1.1%
CVE-2020-8145 MED 6.5 ui unifi_video The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROUP or CUSTOM_GROUP groups, can access the 1.1%