IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2021-37839 MED 4.3 apache superset Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics. 1.4% —
CVE-2019-1171 MED 5.6 microsoft windows_10 An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker 1.4% —
CVE-2024-6913 HIGH 8.8 perkinelmer processplus Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0. 1.4% —
CVE-2024-21447 HIGH 7.8 microsoft windows_10_21h2 Windows Authentication Elevation of Privilege Vulnerability 1.4% —
CVE-2024-21347 HIGH 7.5 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.4% —
CVE-2023-42787 MED 6.5 fortinet fortianalyzer A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web consol 1.4% —
CVE-2019-11700 MED 6.5 mozilla firefox A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affe 1.4% —
CVE-2016-4945 MED 6.1 citrix netscaler_gateway_11.0_firmware Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attackers to inject arbitrary web script or HTML via the NSC_TMAC cookie. 1.4% —
CVE-2015-6356 MED 4.3 cisco socialminer Cross-site scripting (XSS) vulnerability in the WeChat page in Cisco Social Miner 10.0(1) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuw60212. 1.4% —
CVE-2014-3325 MED 4.3 cisco unified_customer_voice_portal Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Customer Voice Portal (CVP) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug IDs CSCuh61711, CSCuh61720, CSCuh61723, CSCuh61726, CSCuh61727, CSCu 1.4% —
CVE-2014-3265 MED 4.3 cisco security_manager Cross-site scripting (XSS) vulnerability in the Auto Update Server (AUS) web framework in Cisco Security Manager 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuo06900. 1.4% —
CVE-2013-1178 HIGH 8.3 cisco cg-os Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before 4.1(2)E1( 1.4% —
CVE-2025-27553 HIGH 7.5 apache commons_vfs Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved fil 1.4% —
CVE-2024-30061 HIGH 7.3 microsoft dynamics_365 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability 1.4% —
CVE-2023-44324 CRIT 9.8 adobe framemaker_publishing_server Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An unauthenticated attacker can abuse this vulnerability to access the API and leak default ad 1.4% —
CVE-2020-4588 HIGH 7.8 ibm i2_ibase IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 184579. 1.4% —
CVE-2019-3587 HIGH 7.2 mcafee total_protection DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.18 allows local users to execute arbitrary code via execution from a compromised folder. 1.4% —
CVE-2018-8116 MED 5.5 microsoft windows_10 A denial of service vulnerability exists in the way that Windows handles objects in memory, aka "Microsoft Graphics Component Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 1.4% —
CVE-2018-15436 MED 6.1 cisco webex_business_suite_31 A vulnerability in the web-based management interface of Cisco Webex Events Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) 1.4% —
CVE-2014-8033 MED 5.0 cisco webex_meetings_server The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID CSCuj40421. 1.4% —
CVE-2006-3567 MED 4.3 juniper dx Cross-site scripting (XSS) vulnerability in the web administration interface logging feature in Juniper Networks (Redline) DX 5.1.x, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the username login field. 1.4% —
CVE-2003-1003 HIGH 7.8 cisco pix_firewall Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set. 1.4% —
CVE-2025-59228 HIGH 8.8 microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.4% —
CVE-2023-21682 MED 5.3 microsoft windows_10_1607 Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability 1.4% —
CVE-2021-43750 MED 5.5 adobe premiere_rush Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitati 1.4% —