IT
58.535 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.535 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2013-6973 MED 4.3 cisco webex_training_center Cisco WebEx Training Center allows remote attackers to discover registration IDs via a crafted URL, aka Bug ID CSCul57121. 2.2% —
CVE-2012-0363 HIGH 9.0 cisco small_business_srp520-u_series_firmware The web interface on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to execute arbitrary commands via unspecified vectors, related to a "command inject 2.2% —
CVE-2022-26477 HIGH 7.5 apache systemds The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered with, may lead to CPU exhaustion. As a fix, we added an upper bound and termination condition in the read and wri 2.2% —
CVE-2019-1337 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, aka 'Windows Update Client Information Disclosure Vulnerability'. 2.2% —
CVE-2022-23273 HIGH 7.1 microsoft dynamics_gp Microsoft Dynamics GP Elevation Of Privilege Vulnerability 2.2% —
CVE-2021-1287 HIGH 7.2 cisco rv132w_firmware A vulnerability in the web-based management interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device 2.2% —
CVE-2020-3531 CRIT 9.8 cisco iot_field_network_director A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end database of an affected system. The vulnerability exists because the affected software does not properly authentica 2.2% —
CVE-2019-0839 MED 4.4 microsoft windows_10 An information disclosure vulnerability exists when the Terminal Services component improperly discloses the contents of its memory, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0838. 2.2% —
CVE-2017-11587 HIGH 7.5 cisco residential_gateway_firmware On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is directory traversal in the filename parameter to the /download.conf URI. 2.2% —
CVE-2014-3343 MED 4.3 cisco ios_xr Cisco IOS XR 5.1 allows remote attackers to cause a denial of service (DHCPv6 daemon crash) via a malformed DHCPv6 packet, aka Bug ID CSCuo59052. 2.2% —
CVE-2011-2547 HIGH 9.0 cisco sa500_software The web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote authenticated users to execute arbitrary commands via crafted parameters to web forms, aka Bug ID CSCtq65681. 2.2% —
CVE-2025-62472 HIGH 7.8 microsoft windows_10_1607 Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. 2.2% —
CVE-2022-39135 CRIT 9.8 apache calcite Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefor 2.2% —
CVE-2020-20907 CRIT 9.1 metinfo metinfo MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_general.class.php and app/system/include/function/file.func.php. 2.2% —
CVE-2000-0150 HIGH 7.5 checkpoint firewall-1 Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt. 2.2% —
CVE-2024-50567 HIGH 7.2 fortinet fortiweb An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input. 2.2% —
CVE-2023-38174 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability 2.2% —
CVE-2016-4966 MED 6.5 fortinet fortiwan The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to download PCAP files via vectors related to the UserName GET parameter. 2.2% —
CVE-2015-3613 CRIT 9.8 fortinet fortimanager A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page 2.2% —
CVE-2012-5222 MED 5.0 hp service_manager_web_tier HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to obtain sensitive information via unspecified vectors. 2.2% —
CVE-2023-49283 MED 5.4 microsoft graph microsoft-graph-core the Microsoft Graph Library for PHP. The Microsoft Graph Beta PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at `vendor/micros 2.2% —
CVE-2023-49282 MED 5.4 microsoft graph msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at vendor/microsoft/micr 2.2% —
CVE-2022-33671 MED 4.9 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 2.2% —
CVE-2022-33669 MED 4.9 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 2.2% —
CVE-2022-33668 MED 4.9 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 2.2% —