58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-3615 | MED 5.4 | fortinet fortimanager_firmware Cross-site scripting (XSS) vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving unspecified parameters and a privilege escalation attack. | 1.2% | — |
| CVE-2013-5552 | MED 6.4 | cisco content_services_gateway Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143 | 1.2% | — |
| CVE-2024-30074 | HIGH 8.0 | microsoft windows_server_2008 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2021-27074 | MED 6.2 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.2% | — |
| CVE-2019-0733 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'. | 1.2% | — |
| CVE-2018-8224 | HIGH 7.0 | microsoft windows_7 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. | 1.2% | — |
| CVE-2018-8169 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library driver improperly handles objects in memory, aka "HIDParser Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8. | 1.2% | — |
| CVE-2018-8119 | MED 5.6 | microsoft c_software_development_kit A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azure IoT SDK Spoofing Vulnerability." This affects C# SDK, C SDK, Java SDK. | 1.2% | — |
| CVE-2018-15329 | HIGH 7.2 | f5 big-ip_access_policy_manager On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restriction | 1.2% | — |
| CVE-2018-15327 | HIGH 7.2 | f5 big-ip_access_policy_manager In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed comman | 1.2% | — |
| CVE-2017-9794 | MED 4.3 | apache geode When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In Apache Geode before 1.2.1, the query results may contain data from another user's concurrently execut | 1.2% | — |
| CVE-2014-3264 | MED 6.3 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software 9.1(.5) and earlier allows remote authenticated users to cause a denial of service (device reload) via crafted attributes in a RADIUS packet, aka Bug ID CSCun69561. | 1.2% | — |
| CVE-2014-0704 | HIGH 7.1 | cisco wireless_lan_controller The IGMP implementation on Cisco Wireless LAN Controller (WLC) devices 4.x, 5.x, 6.x, 7.0 before 7.0.250.0, 7.1, 7.2, and 7.3, when IGMPv3 Snooping is enabled, allows remote attackers to cause a denial of service (memory over-read and device restart) via a cra | 1.2% | — |
| CVE-2008-4545 | MED 4.0 | cisco unity Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8 uses weak permissions for the D:\CommServer\Reports directory, which allows remote authenticated users to obtain sensitive information by reading files in this directory. | 1.2% | — |
| CVE-1999-1367 | MED 4.6 | microsoft internet_explorer Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users. | 1.2% | — |
| CVE-2022-20737 | HIGH 8.5 | cisco adaptive_security_appliance_software A vulnerability in the handler for HTTP authentication for resources accessed through the Clientless SSL VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition o | 1.2% | — |
| CVE-2019-4102 | MED 5.9 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158092. | 1.2% | — |
| CVE-2018-18496 | HIGH 8.8 | mozilla firefox When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This is | 1.2% | — |
| CVE-2017-5069 | MED 6.1 | google chrome Incorrect MIME type of XSS-Protection reports in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to circumvent Cross-Origin Resource Sharing checks via a crafted HTML page. | 1.2% | — |
| CVE-2014-3115 | MED 6.8 | fortinet fortiweb Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Fortinet FortiWeb before 5.2.0 allow remote attackers to hijack the authentication of administrators via system/config/adminadd and other unspecified vectors. | 1.2% | — |
| CVE-2008-1744 | HIGH 7.8 | cisco unified_callmanager The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, and 4.3 before 4.3(2) allows remote attackers to cause a denial of service (service crash) via malformed network | 1.2% | — |
| CVE-2008-1742 | HIGH 7.8 | cisco unified_communications_manager Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP p | 1.2% | — |
| CVE-2026-32194 | CRIT 9.8 | microsoft bing_images Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. | 1.2% | — |
| CVE-2024-38124 | CRIT 9.0 | microsoft windows_server_2008 Windows Netlogon Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2017-6767 | HIGH 7.1 | cisco application_policy_infrastructure_controller A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to gain higher privileges than the account is assigned. The attacker will be granted the privileges of the last user to log in, regardles | 1.2% | — |