57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2007-3097 | HIGH 7.5 | f5 firepass_4100 my.activation.php3 in F5 FirePass 4100 SSL VPN allows remote attackers to execute arbitrary shell commands via shell metacharacters in the username parameter. | 2.2% | — |
| CVE-2023-49283 | MED 5.4 | microsoft graph microsoft-graph-core the Microsoft Graph Library for PHP. The Microsoft Graph Beta PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at `vendor/micros | 2.2% | — |
| CVE-2023-49282 | MED 5.4 | microsoft graph msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at vendor/microsoft/micr | 2.2% | — |
| CVE-2010-4347 | MED 6.9 | linux linux_kernel The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACPI method in the ACPI interpreter tables, related to the acpi_debugfs_init functi | 2.2% | — |
| CVE-2006-3626 | MED 6.2 | linux linux_kernel Race condition in Linux kernel 2.6.17.4 and earlier allows local users to gain root privileges by using prctl with PR_SET_DUMPABLE in a way that causes /proc/self/environ to become setuid root. | 2.2% | — |
| CVE-2023-38174 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 2.2% | — |
| CVE-2016-4966 | MED 6.5 | fortinet fortiwan The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to download PCAP files via vectors related to the UserName GET parameter. | 2.2% | — |
| CVE-2015-3613 | CRIT 9.8 | fortinet fortimanager A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page | 2.2% | — |
| CVE-2012-5222 | MED 5.0 | hp service_manager_web_tier HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to obtain sensitive information via unspecified vectors. | 2.2% | — |
| CVE-2025-62472 | HIGH 7.8 | microsoft windows_10_1607 Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 2.2% | — |
| CVE-2020-20907 | CRIT 9.1 | metinfo metinfo MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_general.class.php and app/system/include/function/file.func.php. | 2.2% | — |
| CVE-2019-0231 | HIGH 7.5 | apache mina Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1. | 2.2% | — |
| CVE-2000-0150 | HIGH 7.5 | checkpoint firewall-1 Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt. | 2.2% | — |
| CVE-2022-23273 | HIGH 7.1 | microsoft dynamics_gp Microsoft Dynamics GP Elevation Of Privilege Vulnerability | 2.2% | — |
| CVE-2021-1287 | HIGH 7.2 | cisco rv132w_firmware A vulnerability in the web-based management interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device | 2.2% | — |
| CVE-2020-3531 | CRIT 9.8 | cisco iot_field_network_director A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end database of an affected system. The vulnerability exists because the affected software does not properly authentica | 2.2% | — |
| CVE-2019-0839 | MED 4.4 | microsoft windows_10 An information disclosure vulnerability exists when the Terminal Services component improperly discloses the contents of its memory, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0838. | 2.2% | — |
| CVE-2018-0278 | MED 6.5 | cisco secure_firewall_management_center A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote attacker to access sensitive data about the system. The vulnerability is due to improper cross-origin domain protections for the WebSocket proto | 2.2% | — |
| CVE-2017-11587 | HIGH 7.5 | cisco residential_gateway_firmware On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is directory traversal in the filename parameter to the /download.conf URI. | 2.2% | — |
| CVE-2014-3343 | MED 4.3 | cisco ios_xr Cisco IOS XR 5.1 allows remote attackers to cause a denial of service (DHCPv6 daemon crash) via a malformed DHCPv6 packet, aka Bug ID CSCuo59052. | 2.2% | — |
| CVE-2013-4366 | CRIT 9.8 | apache httpclient http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification. | 2.2% | — |
| CVE-2011-2547 | HIGH 9.0 | cisco sa500_software The web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote authenticated users to execute arbitrary commands via crafted parameters to web forms, aka Bug ID CSCtq65681. | 2.2% | — |
| CVE-2019-1337 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, aka 'Windows Update Client Information Disclosure Vulnerability'. | 2.2% | — |
| CVE-2021-34441 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-34438 | HIGH 7.8 | microsoft windows_10 Windows Font Driver Host Remote Code Execution Vulnerability | 2.2% | — |