58.628 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.628 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-32786 | MED 4.7 | fedoraproject fedora mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9, `oidc_validate_redirect_url()` doe | 2.4% | — |
| CVE-2020-3361 | HIGH 8.1 | cisco webex_meetings A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to gain unauthorized access to a vulnerable Webex site. The vulnerability is due to improper handling of authentication tokens by a vulnerab | 2.4% | — |
| CVE-2019-12984 | MED 5.5 | linux linux_kernel A NULL pointer dereference vulnerability in the function nfc_genl_deactivate_target() in net/nfc/netlink.c in the Linux kernel before 5.1.13 can be triggered by a malicious user-mode program that omits certain NFC attributes, leading to denial of service. | 2.4% | — |
| CVE-2018-0329 | MED 5.3 | cisco wide_area_application_services A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to read data from an affected device via SNMP. The vul | 2.4% | — |
| CVE-2015-6425 | MED 5.0 | cisco unified_communications_manager The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers to cause a denial of service (subsystem outage) via invalid session tokens, aka Bug ID CSCul83786. | 2.4% | — |
| CVE-2015-4284 | MED 5.0 | cisco ios_xr The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows remote attackers to cause a denial of service (BGP process reload) via malformed BGPv4 packets, aka Bug ID CSCur70670. | 2.4% | — |
| CVE-2014-3369 | HIGH 7.1 | cisco expressway_software The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cause a denial of service (device reload) via crafted SDP packets, aka Bug ID CSCuo42252. | 2.4% | — |
| CVE-2014-3361 | HIGH 7.1 | cisco ios The ALG module in Cisco IOS 15.0 through 15.4 does not properly implement SIP over NAT, which allows remote attackers to cause a denial of service (device reload) via multipart SDP IPv4 traffic, aka Bug ID CSCun54071. | 2.4% | — |
| CVE-2021-28569 | MED 4.3 | adobe media_encoder Adobe Media Encoder version 15.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of th | 2.4% | — |
| CVE-2007-0959 | HIGH 7.8 | cisco asa_5500 Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause a denial of service (device reboot) via malformed TCP packets. | 2.4% | — |
| CVE-2018-0358 | HIGH 7.5 | cisco telepresence_video_communication_server A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to exhaustion of file descr | 2.4% | — |
| CVE-2023-35639 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2022-33678 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2022-33676 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2019-13374 | MED 6.1 | dlink central_wifimanager A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parame | 2.4% | — |
| CVE-2020-16996 | MED 6.5 | microsoft windows_server_2012 Kerberos Security Feature Bypass Vulnerability | 2.4% | — |
| CVE-2020-0638 | HIGH 7.8 | ransomware microsoft windows_10_1709 An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege | 2.4% | |
| CVE-2018-12233 | HIGH 7.8 | canonical ubuntu_linux In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug in JFS can be triggered by calling setxattr twice with two different extended attribute names on the same file. This vulnerability can be triggered by an unpri | 2.4% | — |
| CVE-2013-0942 | MED 4.3 | emc rsa_authentication_agent Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Agent 7.1 before 7.1.1 for Web for Internet Information Services, and 7.1 before 7.1.1 for Web for Apache, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors | 2.4% | — |
| CVE-2021-24105 | HIGH 8.4 | microsoft package_manager_configurations <p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package into a package manager's repository which can be retrieved and used during development, build, and release processes. This insertion could le | 2.4% | — |
| CVE-2021-1299 | HIGH 8.8 | cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more informa | 2.4% | — |
| CVE-2021-1298 | HIGH 8.8 | cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more informa | 2.4% | — |
| CVE-2021-1150 | HIGH 7.2 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilit | 2.4% | — |
| CVE-2021-1149 | HIGH 7.2 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilit | 2.4% | — |
| CVE-2021-1148 | HIGH 7.2 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilit | 2.4% | — |