58.444 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.444 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-5092 | MED 4.9 | fortinet fortiweb Directory traversal vulnerability in Fortinet FortiWeb before 5.5.3 allows remote authenticated administrators with read and write privileges to read arbitrary files by leveraging the autolearn feature. | 1.6% | — |
| CVE-2016-2782 | MED 4.6 | linux linux_kernel The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB de | 1.6% | — |
| CVE-2015-4320 | MED 4.0 | cisco telepresence_video_communication_server_software The Configuration Log File component in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to obtain sensitive information by reading a log file, aka Bug ID CSCuv12340. | 1.6% | — |
| CVE-2013-2940 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2939 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2938 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2937 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2936 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2935 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2934 | HIGH 10.0 | citrix cloudportal_services_manager Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 does not properly restrict access to web services, which has unspecified impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2933 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2026-33264 | CRIT 9.8 | apache airflow A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code execution | 1.6% | — |
| CVE-2023-33140 | MED 6.5 | microsoft onenote Microsoft OneNote Spoofing Vulnerability | 1.6% | — |
| CVE-2021-3058 | HIGH 8.8 | paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 vers | 1.6% | — |
| CVE-2020-0903 | MED 5.4 | microsoft exchange_server A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'. | 1.6% | — |
| CVE-2019-0685 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0803, CVE-2019-0859. | 1.6% | — |
| CVE-2017-12287 | MED 4.3 | cisco expressway A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process on an affected system | 1.6% | — |
| CVE-2016-1368 | HIGH 7.5 | cisco firesight_system_software Cisco FirePOWER System Software 5.3.x through 5.3.0.6 and 5.4.x through 5.4.0.3 on FirePOWER 7000 and 8000 appliances, and on the Advanced Malware Protection (AMP) for Networks component on these appliances, allows remote attackers to cause a denial of service | 1.6% | — |
| CVE-2021-40787 | HIGH 7.8 | adobe premiere_elements Adobe Premiere Elements 20210809.daily.2242976 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction i | 1.7% | — |
| CVE-2021-40786 | HIGH 7.8 | adobe premiere_elements Adobe Premiere Elements 20210809.daily.2242976 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction i | 1.7% | — |
| CVE-2021-40765 | HIGH 7.8 | adobe character_animator Adobe Character Animator version 4.4 (and earlier) is affected by a memory corruption vulnerability when parsing a M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vuln | 1.7% | — |
| CVE-2021-40764 | HIGH 7.8 | adobe character_animator Adobe Character Animator version 4.4 (and earlier) is affected by a memory corruption vulnerability when parsing a M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vuln | 1.7% | — |
| CVE-2021-40763 | HIGH 7.8 | adobe character_animator Adobe Character Animator version 4.4 (and earlier) is affected by a memory corruption vulnerability when parsing a WAF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vuln | 1.7% | — |
| CVE-2021-21172 | HIGH 8.1 | debian debian_linux Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | 1.7% | — |
| CVE-2021-1683 | MED 5.0 | microsoft windows_10 Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software | 1.7% | — |