58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-23838 | MED 6.5 | solarwinds database_performance_analyzer Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. | 1.3% | — |
| CVE-2022-23443 | HIGH 7.5 | fortinet fortisoar An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests. | 1.3% | — |
| CVE-2021-28927 | HIGH 7.8 | libretro retroarch The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platform_win32.c via the accessibility_speak_windows function, which allows attackers who have write access on filesystems that are used by RetroAr | 1.3% | — |
| CVE-2012-0362 | MED 4.3 | cisco ios The extended ACL functionality in Cisco IOS 12.2(58)SE2 and 15.0(1)SE discards all lines that end with a log or time keyword, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending network traffic, aka Bu | 1.3% | — |
| CVE-2007-6053 | HIGH 9.3 | ibm db2_universal_database IBM DB2 UDB 9.1 before Fixpak 4 does not properly handle use of large numbers of file descriptors, which might allow attackers to have an unknown impact involving "memory corruption." NOTE: the vendor description of this issue is too vague to be certain that i | 1.3% | — |
| CVE-2007-5547 | MED 4.3 | cisco ios Cross-site scripting (XSS) vulnerability in Cisco IOS allows remote attackers to inject arbitrary web script or HTML, and execute IOS commands, via unspecified vectors, aka PSIRT-2022590358. NOTE: as of 20071016, the only disclosure is a vague pre-advisory wi | 1.3% | — |
| CVE-2026-24300 | CRIT 9.8 | microsoft azure_front_door Azure Front Door Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2024-20689 | HIGH 7.1 | microsoft windows_server_2012 Secure Boot Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2024-20688 | HIGH 7.1 | microsoft windows_server_2012 Secure Boot Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2023-20009 | MED 6.5 | cisco email_security_appliance A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gai | 1.3% | — |
| CVE-2022-38369 | HIGH 8.8 | apache iotdb Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue. | 1.3% | — |
| CVE-2021-21153 | HIGH 8.8 | fedoraproject fedora Stack buffer overflow in GPU Process in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | 1.3% | — |
| CVE-2021-21152 | HIGH 8.8 | fedoraproject fedora Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1.3% | — |
| CVE-2021-1145 | MED 6.5 | cisco staros A vulnerability in the Secure FTP (SFTP) of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an authenticated, remote attacker to read arbitrary files on an affected device. To exploit this vulnerability, the attacker would need to have valid credent | 1.3% | — |
| CVE-2020-5937 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager On BIG-IP AFM 15.1.0-15.1.0.5, the Traffic Management Microkernel (TMM) may produce a core file while processing layer 4 (L4) behavioral denial-of-service (DoS) traffic. | 1.3% | — |
| CVE-2018-0269 | MED 4.3 | cisco digital_network_architecture_center A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauthenticated, remote attacker to communicate with the Kong API server without restriction. The vulnerability is due to an overly permissive Cro | 1.3% | — |
| CVE-2017-9488 | HIGH 8.8 | cisco dpc3939_firmware The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) and DPC3941T (firmware version DPC3941_2.5s3_PROD_sey) devices allows remote attackers to access the web UI by establishing a session to the wan0 WAN IPv6 addre | 1.3% | — |
| CVE-2003-1004 | MED 5.0 | cisco pix_firewall Cisco PIX firewall 6.2.x through 6.2.3, when configured as a VPN Client, allows remote attackers to cause a denial of service (dropped IPSec tunnel connection) via an IKE Phase I negotiation request to the outside interface of the firewall. | 1.3% | — |
| CVE-2003-1002 | MED 5.0 | cisco catalyst_6500 Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set. | 1.3% | — |
| CVE-2021-34736 | MED 5.3 | cisco unified_computing_system A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insu | 1.3% | — |
| CVE-2021-1394 | MED 5.3 | cisco ios_xe A vulnerability in the ingress traffic manager of Cisco IOS XE Software for Cisco Network Convergence System (NCS) 520 Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the web management interface of an af | 1.3% | — |
| CVE-2021-1243 | MED 5.3 | cisco ios_xr A vulnerability in the Local Packet Transport Services (LPTS) programming of the SNMP with the management plane protection feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to allow connections despite the management plane protec | 1.3% | — |
| CVE-2020-3273 | HIGH 7.5 | cisco 5508_wireless_controller_firmware A vulnerability in the 802.11 Generic Advertisement Service (GAS) frame processing function of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service | 1.3% | — |
| CVE-2020-1116 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the use | 1.3% | — |
| CVE-2020-1072 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerabili | 1.3% | — |