57.080 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.080 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-27474 | MED 6.5 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.8% | — |
| CVE-2025-26672 | MED 6.5 | microsoft windows_10_1507 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.8% | — |
| CVE-2025-26667 | MED 6.5 | microsoft windows_server_2008 Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.8% | — |
| CVE-2025-26664 | MED 6.5 | microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.8% | — |
| CVE-2023-36402 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2013-3498 | MED 4.3 | juniper smartpass Cross-site scripting (XSS) vulnerability in Juniper SmartPass WLAN Security Management before 7.7 MR3 and 8.0 before MR2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 1.8% | — |
| CVE-2011-0944 | HIGH 7.8 | cisco ios Cisco IOS 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (device reload) via malformed IPv6 packets, aka Bug ID CSCtj41194. | 1.8% | — |
| CVE-2010-2835 | HIGH 7.8 | cisco ios Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.0 before 7.0(2a)su3, 7.1su before 7.1(3b)su2, 7.1 before 7.1(5), and 8. | 1.8% | — |
| CVE-2021-43999 | HIGH 8.8 | apache guacamole Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allow a malicious user to assume the identity of another Guacamole user. | 1.8% | — |
| CVE-2021-34451 | MED 5.3 | microsoft office_online_server Microsoft Office Online Server Spoofing Vulnerability | 1.8% | — |
| CVE-2018-8253 | MED 4.6 | microsoft windows_10 An elevation of privilege vulnerability exists when Microsoft Cortana allows arbitrary website browsing on the lockscreen, aka "Microsoft Cortana Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10. | 1.8% | — |
| CVE-2018-4266 | MED 5.9 | apple icloud A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6. | 1.8% | — |
| CVE-2012-5992 | MED 6.8 | cisco 2000_wireless_lan_controller Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via screen | 1.8% | — |
| CVE-2010-1454 | MED 6.8 | vmware tc_server com.springsource.tcserver.serviceability.rmi.JmxSocketListener in VMware SpringSource tc Server Runtime 6.0.19 and 6.0.20 before 6.0.20.D, and 6.0.25.A before 6.0.25.A-SR01, does not properly enforce the requirement for an encrypted (aka s2enc) password, which | 1.8% | — |
| CVE-2009-2517 | MED 4.9 | microsoft windows_server_2003 The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition occurs, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vuln | 1.8% | — |
| CVE-2023-38151 | HIGH 8.8 | microsoft host_integration_server Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2023-36438 | HIGH 7.5 | microsoft windows_10_1507 Windows TCP/IP Information Disclosure Vulnerability | 1.8% | — |
| CVE-2020-2028 | HIGH 7.2 | paloaltonetworks pan-os An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root privileges when uploading a new certificate in FIPS-CC mode. This issue affects: All versions of PAN-OS 7.1 and PAN | 1.8% | — |
| CVE-2018-0458 | MED 6.1 | cisco prime_collaboration_assurance A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected devi | 1.8% | — |
| CVE-2018-0411 | MED 6.1 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an af | 1.8% | — |
| CVE-2018-0406 | MED 6.1 | cisco web_security_appliance A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected or Document Object Model based (DOM-based) cross-site scripting (XSS) attack against a user of th | 1.8% | — |
| CVE-2018-0366 | MED 6.1 | cisco web_security_appliance A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affe | 1.8% | — |
| CVE-2018-0356 | MED 6.1 | cisco webex_meetings A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input valid | 1.8% | — |
| CVE-2018-0354 | MED 6.1 | cisco unity_connection A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient | 1.8% | — |
| CVE-2018-0339 | MED 6.1 | cisco identity_services_engine_software A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to | 1.8% | — |