58.211 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.211 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2009-1162 | MED 4.3 | cisco ironport_asyncos Cross-site scripting (XSS) vulnerability in the Spam Quarantine login page in Cisco IronPort AsyncOS before 6.5.2 on Series C, M, and X appliances allows remote attackers to inject arbitrary web script or HTML via the referrer parameter. | 1.2% | — |
| CVE-2008-2163 | MED 4.3 | ibm lotus_quickr Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to "WYSIWYG editors." | 1.2% | — |
| CVE-2007-5581 | MED 4.3 | cisco unified_meetingplace Multiple cross-site scripting (XSS) vulnerabilities in mpweb/scripts/mpx.dll in Cisco Unified MeetingPlace 5.4 and earlier and 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) FirstName and (2) LastName parameters. | 1.2% | — |
| CVE-2007-4633 | MED 4.3 | cisco call_manager Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to inject arbitrary web script or | 1.2% | — |
| CVE-1999-0160 | HIGH 7.5 | cisco ios Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections. | 1.2% | — |
| CVE-2023-34367 | MED 6.5 | microsoft windows_7 Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows until Windows 8) and in any implementation of TCP/IP, which is vulnerable to the Idle scan attack (including many IoT devices). NOTE: The vendor | 1.2% | — |
| CVE-2020-1426 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1389, CVE-2020-1419. | 1.2% | — |
| CVE-2020-1391 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Agent Activation Runtime (AarSvc) fails to properly handle objects in memory, aka 'Windows Agent Activation Runtime Information Disclosure Vulnerability'. | 1.2% | — |
| CVE-2020-1389 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1419, CVE-2020-1426. | 1.2% | — |
| CVE-2020-1386 | MED 5.5 | microsoft windows_10 An information vulnerability exists when Windows Connected User Experiences and Telemetry Service improperly discloses file information, aka 'Connected User Experiences and Telemetry Service Information Disclosure Vulnerability'. | 1.2% | — |
| CVE-2020-1367 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1389, CVE-2020-1419, CVE-2020-1426. | 1.2% | — |
| CVE-2020-1330 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability'. | 1.2% | — |
| CVE-2012-1868 | MED 6.9 | microsoft windows_xp Race condition in the thread-creation implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3 allows local users to gain privileges via a crafted application, aka "Win32k.sys Race Condition Vulnerability." | 1.2% | — |
| CVE-2012-1867 | HIGH 8.4 | microsoft windows_2003_server Integer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted T | 1.2% | — |
| CVE-2005-3174 | MED 4.6 | microsoft windows_2000 Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long. | 1.2% | — |
| CVE-2005-3171 | MED 4.6 | microsoft windows_2000 Microsoft Windows 2000 before Update Rollup 1 for SP4 records Event ID 1704 to indicate that Group Policy security settings were successfully updated, even when the processing fails such as when Ntuser.pol cannot be accessed, which could cause system administr | 1.2% | — |
| CVE-2025-27017 | MED 6.5 | apache nifi Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance events of those proces | 1.2% | — |
| CVE-2023-36796 | HIGH 7.8 | microsoft .net Visual Studio Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-36794 | HIGH 7.8 | microsoft .net Visual Studio Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-36793 | HIGH 7.8 | microsoft .net Visual Studio Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-36792 | HIGH 7.8 | microsoft .net Visual Studio Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-22375 | HIGH 7.2 | ibm security_verify_privilege_on-premises IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 221681. | 1.2% | — |
| CVE-2021-40774 | MED 5.5 | adobe prelude Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of | 1.2% | — |
| CVE-2021-40773 | MED 5.5 | adobe prelude Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of | 1.2% | — |
| CVE-2021-31978 | MED 5.5 | microsoft malware_protection_engine Microsoft Defender Denial of Service Vulnerability | 1.2% | — |