58.343 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.343 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-8652 | MED 5.4 | microsoft windows_azure_pack_rollup A Cross-site Scripting (XSS) vulnerability exists when Windows Azure Pack does not properly sanitize user-provided input, aka "Windows Azure Pack Cross Site Scripting Vulnerability." This affects Windows Azure Pack Rollup 13.1. | 1.5% | — |
| CVE-2004-1112 | MED 5.1 | cisco security_agent The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer ove | 1.5% | — |
| CVE-2025-21380 | HIGH 8.8 | microsoft azure_marketplace Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network. | 1.5% | — |
| CVE-2023-36873 | HIGH 7.4 | microsoft .net_framework .NET Framework Spoofing Vulnerability | 1.5% | — |
| CVE-2022-37978 | HIGH 7.5 | microsoft windows_10 Windows Active Directory Certificate Services Security Feature Bypass | 1.5% | — |
| CVE-2021-31385 | HIGH 8.8 | juniper junos An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in J-Web of Juniper Networks Junos OS allows any low-privileged authenticated attacker to elevate their privileges to root. This issue affects: Juniper Networks Jun | 1.5% | — |
| CVE-2011-1570 | LOW 3.5 | liferay liferay_portal Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to inject arbitrary web script or HTML via a message title, a different vulnerability than CVE- | 1.5% | — |
| CVE-2002-1099 | MED 5.0 | cisco vpn_3000_concentrator_series_software Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages. | 1.5% | — |
| CVE-2024-26231 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2024-26227 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2022-20720 | MED 5.5 | cisco ios_xe Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system | 1.5% | — |
| CVE-2021-29825 | HIGH 7.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP. IBM X-Force ID: 204470. | 1.5% | — |
| CVE-2013-1217 | MED 6.8 | cisco ios The generic input/output control implementation in Cisco IOS does not properly manage buffers, which allows remote authenticated users to cause a denial of service (device reload) by sending many SNMP requests at the same time, aka Bug ID CSCub41105. | 1.5% | — |
| CVE-2002-1692 | LOW 3.6 | microsoft windows_95 Buffer overflow in backup utility of Microsoft Windows 95 allows attackers to execute arbitrary code by causing a filename with a long extension to be placed in a folder to be backed up. | 1.5% | — |
| CVE-2023-20076 | HIGH 7.2 | cisco 807_industrial_integrated_services_router_firmware A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to incomplete sanitization of parameters tha | 1.5% | — |
| CVE-2022-21891 | HIGH 7.6 | microsoft dynamics_365_sales Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability | 1.5% | — |
| CVE-2022-21839 | MED 6.1 | microsoft windows_10 Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability | 1.5% | — |
| CVE-2020-1377 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. A locally authenticated atta | 1.5% | — |
| CVE-2013-0889 | MED 6.8 | google chrome Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement before proceeding with a file download, which might make it easier for remote attackers to execute arbitrary code | 1.5% | — |
| CVE-2012-5017 | MED 6.8 | cisco asr_1001 Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device reload) by establishing a VPN session and then sending malformed IKEv2 packets, aka Bug ID CSCub39268. | 1.5% | — |
| CVE-2024-21305 | MED 4.4 | microsoft windows_10_1809 Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability | 1.5% | — |
| CVE-2022-22952 | CRIT 9.1 | vmware carbon_black_app_control VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface m | 1.5% | — |
| CVE-2020-1591 | MED 5.4 | microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially cr | 1.5% | — |
| CVE-2020-0891 | MED 5.4 | microsoft sharepoint_enterprise_server This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePo | 1.5% | — |
| CVE-2016-7917 | MED 5.0 | linux linux_kernel The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a batch message's length field is large enough, which allows local users to obtain sensitive information from kernel memory or cause a denial of | 1.5% | — |