57.411 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.411 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-21839 | MED 6.1 | microsoft windows_10 Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability | 1.5% | — |
| CVE-2020-1377 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. A locally authenticated atta | 1.5% | — |
| CVE-2013-0889 | MED 6.8 | google chrome Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement before proceeding with a file download, which might make it easier for remote attackers to execute arbitrary code | 1.5% | — |
| CVE-2012-5017 | MED 6.8 | cisco asr_1001 Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device reload) by establishing a VPN session and then sending malformed IKEv2 packets, aka Bug ID CSCub39268. | 1.5% | — |
| CVE-2024-26231 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2024-26227 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2022-20720 | MED 5.5 | cisco ios_xe Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system | 1.5% | — |
| CVE-2021-44171 | CRIT 9.0 | fortinet fortios A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.3 allows | 1.5% | — |
| CVE-2021-29825 | HIGH 7.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP. IBM X-Force ID: 204470. | 1.5% | — |
| CVE-2013-1217 | MED 6.8 | cisco ios The generic input/output control implementation in Cisco IOS does not properly manage buffers, which allows remote authenticated users to cause a denial of service (device reload) by sending many SNMP requests at the same time, aka Bug ID CSCub41105. | 1.5% | — |
| CVE-2002-1692 | LOW 3.6 | microsoft windows_95 Buffer overflow in backup utility of Microsoft Windows 95 allows attackers to execute arbitrary code by causing a filename with a long extension to be placed in a folder to be backed up. | 1.5% | — |
| CVE-2025-21380 | HIGH 8.8 | microsoft azure_marketplace Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network. | 1.5% | — |
| CVE-2023-36873 | HIGH 7.4 | microsoft .net_framework .NET Framework Spoofing Vulnerability | 1.5% | — |
| CVE-2021-31385 | HIGH 8.8 | juniper junos An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in J-Web of Juniper Networks Junos OS allows any low-privileged authenticated attacker to elevate their privileges to root. This issue affects: Juniper Networks Jun | 1.5% | — |
| CVE-2011-1570 | LOW 3.5 | liferay liferay_portal Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to inject arbitrary web script or HTML via a message title, a different vulnerability than CVE- | 1.5% | — |
| CVE-2002-1099 | MED 5.0 | cisco vpn_3000_concentrator_series_software Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages. | 1.5% | — |
| CVE-2023-24881 | MED 6.5 | microsoft teams Microsoft Teams Information Disclosure Vulnerability | 1.5% | — |
| CVE-2022-41122 | MED 6.5 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.5% | — |
| CVE-2022-34662 | MED 6.5 | apache dolphinscheduler When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher | 1.5% | — |
| CVE-2022-22188 | HIGH 7.5 | juniper junos An Uncontrolled Memory Allocation vulnerability leading to a Heap-based Buffer Overflow in the packet forwarding engine (PFE) of Juniper Networks Junos OS allows a network-based unauthenticated attacker to flood the device with traffic leading to a Denial of S | 1.5% | — |
| CVE-2021-32791 | MED 5.9 | fedoraproject fedora mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, the AES GCM encrypti | 1.5% | — |
| CVE-2018-8652 | MED 5.4 | microsoft windows_azure_pack_rollup A Cross-site Scripting (XSS) vulnerability exists when Windows Azure Pack does not properly sanitize user-provided input, aka "Windows Azure Pack Cross Site Scripting Vulnerability." This affects Windows Azure Pack Rollup 13.1. | 1.5% | — |
| CVE-2004-1112 | MED 5.1 | cisco security_agent The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer ove | 1.5% | — |
| CVE-1999-1322 | MED 4.6 | broadcom arcserve_backup The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext. | 1.5% | — |
| CVE-2021-41831 | MED 5.3 | apache openoffice It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25634 for the LibreOffice advisory. | 1.5% | — |