IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2007-1945 HIGH 7.5 ibm websphere_application_server Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors. 1.4% —
CVE-2022-0564 MED 5.3 qlik qlik_sense A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow the at 1.4% —
CVE-2021-40484 HIGH 7.6 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 1.4% —
CVE-2021-40483 HIGH 7.6 microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability 1.4% —
CVE-2020-3482 MED 6.5 cisco expressway A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations. The vulnerability is 1.4% —
CVE-2020-3368 MED 5.8 cisco asyncos A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to ins 1.4% —
CVE-2020-3133 HIGH 7.5 cisco email_security_appliance A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device. The vulnerability is due to improper validation of inco 1.4% —
CVE-2013-1157 MED 4.3 cisco prime_central_for_hosted_collaboration_solution Cross-site scripting (XSS) vulnerability in the IBM Tivoli Monitoring (ITM) Java servlet container in Cisco Prime Central for Hosted Collaboration Solution allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID 1.4% —
CVE-2003-1001 MED 5.0 cisco catalyst_6500 Buffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via HTTP auth requests for (1) TACACS+ or (2) RADIUS authentication. 1.4% —
CVE-2000-0654 MED 4.6 microsoft sql_server Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability. 1.4% —
CVE-2023-25926 MED 5.5 ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume m 1.4% —
CVE-2022-40954 MED 5.5 apache airflow Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to DAG files 1.4% —
CVE-2019-11837 HIGH 7.5 f5 njs njs through 0.3.1, used in NGINX, has a segmentation fault in String.prototype.toBytes for negative arguments, related to nxt_utf8_next in nxt/nxt_utf8.h and njs_string_offset in njs/njs_string.c. 1.4% —
CVE-2017-12345 MED 4.7 cisco data_center_network_manager Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client inter 1.4% —
CVE-2016-6408 HIGH 7.5 cisco prime_home Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCvb17814. 1.4% —
CVE-2008-3820 MED 6.8 cisco security_manager Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain "root access" to IEV via unspecified use of TCP sessions to these por 1.4% —
CVE-2016-1366 MED 6.5 cisco ios_xr The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID 1.4% —
CVE-2014-3294 MED 4.0 cisco webex_meetings_server Cisco WebEx Meeting Server does not properly restrict the content of URLs, which allows remote authenticated users to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug ID CSCuj8 1.4% —
CVE-2014-0743 MED 5.0 cisco unified_communications_manager The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and modify registered-device information via crafted data, aka Bug ID CSCum95468 1.4% —
CVE-2013-0895 HIGH 7.5 google chrome Google Chrome before 25.0.1364.97 on Linux, and before 25.0.1364.99 on Mac OS X, does not properly handle pathnames during copy operations, which might make it easier for remote attackers to execute arbitrary programs via unspecified vectors. 1.4% —
CVE-2012-0941 MED 6.1 fortinet fortios Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Endpoint Monitor, (2) Dialup List, or (3) L 1.4% —
CVE-2024-21416 HIGH 8.1 microsoft windows_10_1809 Windows TCP/IP Remote Code Execution Vulnerability 1.4% —
CVE-2023-37536 HIGH 8.2 apache xerces-c\+\+ An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. 1.4% —
CVE-2023-36736 MED 4.4 microsoft identity_linux_broker Microsoft Identity Linux Broker Remote Code Execution Vulnerability 1.4% —
CVE-2023-21693 MED 5.7 microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.4% —