58.285 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.285 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-3417 | MED 5.0 | cisco video_surveillance_operations_manager The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication, which allows remote attackers to watch video feeds via a crafted URL, aka Bug ID CSCtg72262. | 1.3% | — |
| CVE-2013-1123 | MED 4.3 | cisco unified_meetingplace Multiple cross-site scripting (XSS) vulnerabilities in the server in Cisco Unified MeetingPlace 7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuc65411 and CSCue18706. | 1.3% | — |
| CVE-2007-6477 | MED 4.3 | citrix web_interface Cross-site scripting (XSS) vulnerability in the on-line help feature in Citrix Web Interface 2.0 and earlier, and NFuse, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 1.3% | — |
| CVE-2003-1306 | LOW 2.6 | Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in th | 1.3% | — |
| CVE-2019-0039 | HIGH 8.1 | juniper junos If REST API is enabled, the Junos OS login credentials are vulnerable to brute force attacks. The high default connection limit of the REST API may allow an attacker to brute-force passwords using advanced scripting techniques. Additionally, administrators who | 1.3% | — |
| CVE-2018-11087 | MED 5.9 | pivotal_software spring_advanced_message_queuing_protocol Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit. | 1.3% | — |
| CVE-2018-0380 | MED 5.5 | cisco webex_meetings_online Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious .arf or .wrf file via em | 1.3% | — |
| CVE-2017-7681 | HIGH 8.8 | apache openmeetings Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end. | 1.3% | — |
| CVE-2013-1134 | HIGH 7.1 | cisco unified_communications_manager The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9.x before 9.1(1) does not require authentication from the remote LBM Hub node, which allows remote attackers to conduct cache-poisoning atta | 1.3% | — |
| CVE-2024-49147 | CRIT 9.3 | microsoft update_catalog Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver. | 1.3% | — |
| CVE-2024-21443 | HIGH 7.3 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2023-34189 | MED 6.5 | apache inlong Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate o | 1.3% | — |
| CVE-2023-1017 | HIGH 7.8 | microsoft windows_10_1507 An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of s | 1.3% | — |
| CVE-2021-1400 | HIGH 8.8 | cisco wap125_firmware Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to obtain sensitive information from or inject arbitrary commands on an | 1.3% | — |
| CVE-2016-1445 | MED 5.3 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software 8.2 through 9.4.3.3 allows remote attackers to bypass intended ICMP Echo Reply ACLs via vectors related to subtypes. | 1.3% | — |
| CVE-2024-33508 | HIGH 7.3 | fortinet forticlient_enterprise_management_server An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations | 1.3% | — |
| CVE-2023-41748 | CRIT 9.8 | acronis cloud_manager Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203. | 1.3% | — |
| CVE-2023-41746 | CRIT 9.8 | acronis cloud_manager Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203. | 1.3% | — |
| CVE-2022-21876 | MED 5.5 | microsoft windows_10 Win32k Information Disclosure Vulnerability | 1.3% | — |
| CVE-2021-31948 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.3% | — |
| CVE-2019-1881 | MED 4.7 | cisco industrial_network_director A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vuln | 1.3% | — |
| CVE-2022-20822 | HIGH 7.1 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied in | 1.3% | — |
| CVE-2020-1662 | HIGH 7.5 | juniper junos On Juniper Networks Junos OS and Junos OS Evolved devices, BGP session flapping can lead to a routing process daemon (RPD) crash and restart, limiting the attack surface to configured BGP peers. This issue only affects devices with BGP damping in combination w | 1.3% | — |
| CVE-2020-1657 | HIGH 7.5 | juniper junos On SRX Series devices, a vulnerability in the key-management-daemon (kmd) daemon of Juniper Networks Junos OS allows an attacker to spoof packets targeted to IPSec peers before a security association (SA) is established thereby causing a failure to set up the | 1.3% | — |
| CVE-2025-53719 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1.3% | — |