58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2012-2495 | MED 4.3 | cisco anyconnect_secure_mobility_client The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 and Cisco Secure Desktop before 3.6.6020 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attacke | 1.4% | — |
| CVE-2012-2494 | MED 4.3 | cisco anyconnect_secure_mobility_client The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 and 3.x before 3.0 MR8 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attac | 1.4% | — |
| CVE-2011-0396 | HIGH 7.8 | cisco adaptive_security_appliance Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.23), 8.1 before 8.1(2.49), 8.2 before 8.2(4.1), and 8.3 before 8.3(2.13), when a Certificate Authority (CA) is configured, allow remote attackers to read arbitrary file | 1.4% | — |
| CVE-2020-3480 | HIGH 8.6 | cisco ios_xe Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload or stop forwarding traffic through the firewall. The vulnerabilities are due to incomplete handli | 1.4% | — |
| CVE-2020-17147 | HIGH 8.7 | microsoft dynamics_365 Dynamics CRM Webclient Cross-site Scripting Vulnerability | 1.4% | — |
| CVE-2020-17098 | MED 5.5 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-17094 | MED 5.5 | microsoft windows_10 Windows Error Reporting Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-1148 | MED 5.4 | microsoft sharepoint_enterprise_server A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1289. | 1.4% | — |
| CVE-2026-0261 | HIGH 7.2 | paloaltonetworks pan-os Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the | 1.4% | — |
| CVE-2021-22009 | HIGH 7.5 | vmware cloud_foundation The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of service condition due to excessive memory c | 1.4% | — |
| CVE-2019-0816 | MED 5.1 | canonical ubuntu_linux A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'. | 1.4% | — |
| CVE-2017-6128 | HIGH 7.5 | f5 big-ip_access_policy_manager An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 BIG-IP, Enterprise Manager, BIG-IQ, and iWorkflow. | 1.4% | — |
| CVE-2016-0898 | CRIT 10.0 | vmware pivotal_software_mysql MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM. | 1.4% | — |
| CVE-2008-2674 | MED 6.4 | fujitsu interstage_application_server_enterprise Unspecified vulnerability in the Interstage Management Console, as used in Fujitsu Interstage Application Server 6.0 through 9.0.0A, Apworks Modelers-J 6.0 through 7.0, and Studio 8.0.1 and 9.0.0, allows remote attackers to read or delete arbitrary files via u | 1.4% | — |
| CVE-2024-38029 | HIGH 7.5 | microsoft windows_server_2022_23h2 Microsoft OpenSSH for Windows Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-35316 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Information Disclosure Vulnerability | 1.4% | — |
| CVE-2021-1303 | HIGH 8.8 | cisco catalyst_center A vulnerability in the user management roles of Cisco DNA Center could allow an authenticated, remote attacker to execute unauthorized commands on an affected device. The vulnerability is due to improper enforcement of actions for assigned user roles. An attac | 1.4% | — |
| CVE-2020-3559 | HIGH 8.6 | cisco access_points A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper handling of clients that are trying to connect to the AP. An attacker could | 1.4% | — |
| CVE-2019-6644 | CRIT 9.4 | f5 big-ip_access_policy_manager Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a debug nodejs process to all interfaces when invoked. This may expose the process to unauthorized users if the p | 1.4% | — |
| CVE-2019-15286 | HIGH 7.8 | cisco webex_business_suite Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validatio | 1.4% | — |
| CVE-2019-15284 | HIGH 7.8 | cisco webex_business_suite Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validatio | 1.4% | — |
| CVE-2005-2245 | HIGH 7.5 | f5 tmos Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors, possibly involving NATIVE ciphers. | 1.4% | — |
| CVE-2025-25005 | MED 6.5 | microsoft exchange_server Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | 1.4% | — |
| CVE-2020-1603 | HIGH 8.6 | juniper junos Specific IPv6 packets sent by clients processed by the Routing Engine (RE) are improperly handled. These IPv6 packets are designed to be blocked by the RE from egressing the RE. Instead, the RE allows these specific IPv6 packets to egress the RE, at which poin | 1.4% | — |
| CVE-2014-0667 | MED 6.3 | cisco secure_access_control_system The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated users to read arbitrary files via a request to this interface, aka Bug ID CSCud75169. | 1.4% | — |