58.559 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.559 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-38435 | MED 6.1 | apache felix_health_check_webconsole_plugin An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. | 2.2% | — |
| CVE-2021-33782 | MED 5.5 | microsoft windows_10 Windows Authenticode Spoofing Vulnerability | 2.2% | — |
| CVE-2019-7237 | HIGH 7.5 | idreamsoft icms An issue was discovered in idreamsoft iCMS 7.0.13 on Windows. editor/editor.admincp.php allows admincp.php?app=files&do=browse ..\ Directory Traversal. | 2.2% | — |
| CVE-2017-12354 | MED 5.3 | cisco secure_access_control_system A vulnerability in the web-based interface of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected software does not sufficie | 2.2% | — |
| CVE-2020-5868 | CRIT 9.8 | f5 big-iq_centralized_management In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell commands on affected systems using HTTP requests to the BIG-IQ user interface. | 2.2% | — |
| CVE-2020-2010 | HIGH 7.2 | paloaltonetworks pan-os An OS command injection vulnerability in PAN-OS management interface allows an authenticated administrator to execute arbitrary OS commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; P | 2.2% | — |
| CVE-2020-2007 | HIGH 7.2 | paloaltonetworks pan-os An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to potentially execute arbitrary commands with root privileges. This issue affects: All PAN-OS 7.1 versions; PAN-OS 8.1 versions earlier than 8.1.14 | 2.2% | — |
| CVE-2019-1631 | MED 5.3 | cisco integrated_management_controller A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitive system usage information. The vulnerability is due to a lack of proper data pr | 2.2% | — |
| CVE-2022-30142 | HIGH 7.5 | microsoft windows_10 Windows File History Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-45052 | LOW 3.3 | adobe bridge Adobe Bridge version 11.1.2 (and earlier) and version 12.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex | 2.3% | — |
| CVE-2021-31914 | CRIT 9.8 | jetbrains teamcity In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible. | 2.3% | — |
| CVE-2013-0892 | HIGH 7.5 | google chrome Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors. | 2.3% | — |
| CVE-2022-33649 | CRIT 9.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 2.3% | — |
| CVE-2022-24948 | MED 6.1 | apache jspwiki A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information ab | 2.3% | — |
| CVE-2016-8438 | CRIT 9.8 | linux linux_kernel Integer overflow leading to a TOCTOU condition in hypervisor PIL. An integer overflow exposes a race condition that may be used to bypass (Peripheral Image Loader) PIL authentication. Product: Android. Versions: Kernel 3.18. Android ID: A-31624565. References: | 2.3% | — |
| CVE-2014-3340 | MED 4.0 | cisco webex_meetmenow Directory traversal vulnerability in an unspecified PHP script in the server in Cisco WebEx MeetMeNow allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCuo16166. | 2.3% | — |
| CVE-2020-9666 | MED 5.5 | adobe campaign Adobe Campaign Classic before 20.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.3% | — |
| CVE-2019-1334 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1345. | 2.3% | — |
| CVE-2024-43602 | CRIT 9.9 | microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-31940 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-31192 | HIGH 7.8 | microsoft windows_10 Windows Media Foundation Core Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28470 | HIGH 7.8 | microsoft visual_studio_code_github_pull_requests_and_issues Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28466 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28464 | HIGH 7.8 | microsoft vp9_video_extensions VP9 Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2018-8431 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.3% | — |