57.080 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.080 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-46819 | MED 5.3 | apache ofbiz Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09. Users are recommended to upgrade to version 18.12.09 | 1.8% | — |
| CVE-2023-21741 | HIGH 7.1 | microsoft 365_apps Microsoft Office Visio Information Disclosure Vulnerability | 1.8% | — |
| CVE-2022-43550 | CRIT 9.8 | jitsi jitsi A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the opportunity to remote execution. | 1.8% | — |
| CVE-2015-1647 | LOW 2.1 | microsoft windows_8.1 Virtual Machine Manager (VMM) in Hyper-V in Microsoft Windows 8.1 and Windows Server 2012 R2 allows guest OS users to cause a denial of service (VMM functionality loss) via a crafted application, aka "Windows Hyper-V DoS Vulnerability." | 1.8% | — |
| CVE-2025-21208 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2025-21201 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Server Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2025-21200 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2025-21190 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2022-31703 | HIGH 7.5 | vmware vrealize_log_insight The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. | 1.8% | — |
| CVE-2022-24969 | MED 6.1 | apache dubbo bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability. | 1.8% | — |
| CVE-2020-3443 | HIGH 8.8 | cisco smart_software_manager_on-prem A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and execute commands with higher privileges. The vulnerability is due to insufficient authorization of the System Operator | 1.8% | — |
| CVE-2020-17509 | HIGH 7.5 | apache traffic_server ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected. | 1.8% | — |
| CVE-2018-3195 | MED 5.5 | netapp oncommand_insight Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to c | 1.8% | — |
| CVE-2015-0594 | MED 4.3 | cisco prime_lan_management_solution Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS) and Cisco Security Manager, allow remote attackers to inject arbitrary web script or HTML via unspecified param | 1.8% | — |
| CVE-2014-8026 | MED 4.3 | cisco jabber_guest Cross-site scripting (XSS) vulnerability in the Guest Server in Cisco Jabber allows remote attackers to inject arbitrary web script or HTML via a (1) GET or (2) POST parameter, aka Bug ID CSCus08074. | 1.8% | — |
| CVE-2014-8022 | MED 4.3 | cisco identity_services_engine_software Multiple cross-site scripting (XSS) vulnerabilities in Cisco Identity Services Engine allow remote attackers to inject arbitrary web script or HTML via input to unspecified web pages, aka Bug IDs CSCur69835 and CSCur69776. | 1.8% | — |
| CVE-2014-8021 | MED 4.3 | cisco anyconnect_secure_mobility_client Cross-site scripting (XSS) vulnerability in Cisco AnyConnect Secure Mobility Client 3.1(.02043) and earlier and Cisco HostScan Engine 3.1(.05183) and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving an applet-path UR | 1.8% | — |
| CVE-2014-3378 | MED 5.0 | cisco ios_xr tacacsd in Cisco IOS XR 5.1 and earlier allows remote attackers to cause a denial of service (process reload) via a malformed TACACS+ packet, aka Bug ID CSCum00468. | 1.8% | — |
| CVE-2014-3365 | MED 4.3 | cisco prime_security_manager Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID CSCuo9 | 1.8% | — |
| CVE-2014-2336 | MED 4.3 | fortinet fortianalyzer_firmware Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 and FortiAnalyzer before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability | 1.8% | — |
| CVE-2014-0735 | MED 4.3 | cisco unified_communications_manager Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCum464 | 1.8% | — |
| CVE-2013-6962 | MED 4.3 | cisco webex_meeting_center Cross-site scripting (XSS) vulnerability in the mobile-browser subsystem in Cisco WebEx Meeting Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36228. | 1.8% | — |
| CVE-2013-6961 | MED 4.3 | cisco webex_meeting_center Cross-site scripting (XSS) vulnerability in the Collaboration Partner Access Console (CPAC) in Cisco WebEx Meeting Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36237. | 1.8% | — |
| CVE-2013-6916 | MED 4.3 | cybozu garoon Cross-site scripting (XSS) vulnerability in the Yahoo! User Interface Library in Cybozu Garoon before 3.7.2, when Internet Explorer 9 or 10 or Chrome is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 1.8% | — |
| CVE-2013-5483 | MED 4.3 | cisco socialminer Cross-site scripting (XSS) vulnerability in bookmarklet.jsp in Cisco SocialMiner allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuh73868. | 1.8% | — |