57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2011-4739 | HIGH 10.0 | parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demo | 2.2% | — |
| CVE-2011-4730 | HIGH 10.0 | parallels parallels_plesk_panel The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended works | 2.2% | — |
| CVE-2022-37981 | MED 4.3 | microsoft windows_10 Windows Event Logging Service Denial of Service Vulnerability | 2.2% | — |
| CVE-2016-4762 | HIGH 8.8 | apple icloud WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, iCloud before 6.0 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. | 2.2% | — |
| CVE-2012-4145 | HIGH 10.0 | opera opera_browser Unspecified vulnerability in Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, has unknown impact and attack vectors, related to a "low severity issue." | 2.2% | — |
| CVE-2018-15446 | MED 5.3 | cisco meeting_server A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper protections on data that is returned from user meeting requests when the Guest access via ID a | 2.2% | — |
| CVE-2017-11880 | MED 4.7 | microsoft windows_10 Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to run a specially crafted application and obtain informa | 2.2% | — |
| CVE-2017-11849 | MED 4.7 | microsoft windows_10 Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially | 2.2% | — |
| CVE-2017-11842 | MED 4.7 | microsoft windows_10 Windows kernel in Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted application due to the Windows kernel impr | 2.2% | — |
| CVE-2011-4348 | HIGH 7.1 | linux linux_kernel Race condition in the sctp_rcv function in net/sctp/input.c in the Linux kernel before 2.6.29 allows remote attackers to cause a denial of service (system hang) via SCTP packets. NOTE: in some environments, this issue exists because of an incomplete fix for C | 2.2% | — |
| CVE-2023-36723 | HIGH 7.8 | microsoft windows_10_1809 Windows Container Manager Service Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2021-42294 | HIGH 7.2 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2018-4374 | MED 6.1 | apple icloud A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8. | 2.2% | — |
| CVE-2017-12214 | HIGH 8.8 | cisco unified_customer_voice_portal A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is | 2.2% | — |
| CVE-2024-21756 | HIGH 8.8 | fortinet fortisandbox A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized | 2.2% | — |
| CVE-2022-33650 | MED 4.9 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2019-18909 | HIGH 8.0 | hp thinpro The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges. | 2.2% | — |
| CVE-2016-7221 | HIGH 7.8 | microsoft windows_10 Input Method Editor (IME) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 mishandles DLL loading, which al | 2.2% | — |
| CVE-2020-3131 | MED 6.5 | cisco webex_teams A vulnerability in the Cisco Webex Teams client for Windows could allow an authenticated, remote attacker to cause the client to crash, resulting in a denial of service (DoS) condition. The attacker needs a valid developer account to exploit this vulnerability | 2.2% | — |
| CVE-2007-5568 | HIGH 7.1 | cisco adaptive_security_appliance_software Cisco PIX and ASA appliances with 7.0 through 8.0 software, and Cisco Firewall Services Module (FWSM) 3.1(5) and earlier, allow remote attackers to cause a denial of service (device reload) via a crafted MGCP packet, aka CSCsi90468 (appliance) and CSCsi00694 ( | 2.2% | — |
| CVE-2019-17658 | CRIT 9.8 | fortinet forticlient An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path. | 2.2% | — |
| CVE-2018-13094 | MED 5.5 | canonical ubuntu_linux An issue was discovered in fs/xfs/libxfs/xfs_attr_leaf.c in the Linux kernel through 4.17.3. An OOPS may occur for a corrupted xfs image after xfs_da_shrink_inode() is called with a NULL bp. | 2.2% | — |
| CVE-2016-1302 | HIGH 8.8 | cisco nx-os Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RB | 2.2% | — |
| CVE-2024-24916 | MED 6.5 | checkpoint smartconsole Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin). | 2.2% | — |
| CVE-2017-15805 | HIGH 7.5 | cisco small_business_sa520_firmware Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files. | 2.2% | — |