IT
57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.057 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2015-0739 MED 4.0 cisco firesight_system_software The Lights-Out Management (LOM) implementation in Cisco FireSIGHT System Software 5.3.0 on Sourcefire 3D Sensor devices allows remote authenticated users to perform arbitrary Baseboard Management Controller (BMC) file uploads via unspecified vectors, aka Bug I 2.0%
CVE-2014-3393 MED 4.3 cisco adaptive_security_appliance_software The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), and 9.2 before 9.2(2.4) does not properly implement 2.0%
CVE-2010-0151 HIGH 7.8 cisco firewall_services_module The Cisco Firewall Services Module (FWSM) 4.0 before 4.0(8), as used in for the Cisco Catalyst 6500 switches, Cisco 7600 routers, and ASA 5500 Adaptive Security Appliances, allows remote attackers to cause a denial of service (crash) via a malformed Skinny Cli 2.0%
CVE-2010-0142 HIGH 8.5 cisco unified_meetingplace MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote authenticated users to gain privileges via a modified authentication sequence, aka Bug ID CSCsv66530. 2.0%
CVE-2002-2140 MED 5.0 cisco pix_firewall_software Buffer overflow in Cisco PIX Firewall 5.2.x to 5.2.8, 6.0.x to 6.0.3, 6.1.x to 6.1.3, and 6.2.x to 6.2.1 allows remote attackers to cause a denial of service via HTTP traffic authentication using (1) TACACS+ or (2) RADIUS. 2.0%
CVE-2021-23043 MED 6.5 f5 big-ip_access_policy_manager On BIG-IP, on all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to access arbitrary files. Note: Software ve 2.0%
CVE-2016-8748 MED 5.4 apache nifi In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM. 2.0%
CVE-2010-2428 MED 4.3 wftpserver wing_ftp_server Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request. 2.0%
CVE-2022-24472 HIGH 8.0 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 2.0%
CVE-2016-1402 HIGH 7.5 cisco identity_services_engine_software The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Passw 2.0%
CVE-2015-4233 MED 6.5 cisco unified_meetingplace SQL injection vulnerability in Cisco Unified MeetingPlace 8.6(1.2) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuu54037. 2.0%
CVE-2015-4222 MED 6.5 cisco unified_communications_manager_im_and_presence_service SQL injection vulnerability in Cisco Unified Communications Manager IM and Presence Service 9.1(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq46325. 2.0%
CVE-2024-29993 HIGH 8.8 microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability 2.0%
CVE-2021-42310 HIGH 8.1 microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability 2.0%
CVE-2012-1511 MED 4.3 vmware view Cross-site scripting (XSS) vulnerability in View Manager Portal in VMware View before 4.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. 2.0%
CVE-2011-2581 MED 5.0 cisco nexus_3000 The ACL implementation in Cisco NX-OS 5.0(2) and 5.0(3) before 5.0(3)N2(1) on Nexus 5000 series switches, and NX-OS before 5.0(3)U1(2a) on Nexus 3000 series switches, does not properly handle comments in conjunction with deny statements, which allows remote at 2.0%
CVE-2006-4909 LOW 2.6 cisco guard_ddos_mitigation_appliance Cross-site scripting (XSS) vulnerability in Cisco Guard DDoS Mitigation Appliance before 5.1(6), when anti-spoofing is enabled, allows remote attackers to inject arbitrary web script or HTML via certain character sequences in a URL that are not properly handle 2.0%
CVE-2026-58289 CRIT 9.0 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 2.0%
CVE-2025-53506 HIGH 7.5 apache tomcat Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10 2.0%
CVE-2021-44040 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1. 2.0%
CVE-2020-9558 LOW 3.3 adobe bridge Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. 2.0%
CVE-2024-20654 HIGH 8.0 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 2.0%
CVE-2023-36423 HIGH 8.8 microsoft windows_10_1507 Microsoft Remote Registry Service Remote Code Execution Vulnerability 2.0%
CVE-2019-1091 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when Unistore.dll fails to properly handle objects in memory, aka 'Microsoft unistore.dll Information Disclosure Vulnerability'. 2.0%
CVE-2014-3270 MED 5.0 cisco ios_xr The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (process hang) via a malformed packet, aka Bug ID CSCul80924. 2.0%