57.415 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.415 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-40712 | MED 6.5 | apache airflow Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be mask | 1.5% | — |
| CVE-2022-43670 | MED 5.4 | apache sling_cms An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the t | 1.5% | — |
| CVE-2021-1230 | HIGH 8.6 | cisco nx-os A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a routing process to crash, which could lead to a denia | 1.5% | — |
| CVE-2020-36385 | HIGH 7.8 | linux linux_kernel An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id situations where ucma_close is called, aka CID-f5449e74802c. | 1.5% | — |
| CVE-2019-16021 | HIGH 7.5 | cisco ios_xr Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due | 1.5% | — |
| CVE-2017-5108 | HIGH 8.8 | google chrome Type confusion in PDFium in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to potentially maliciously modify objects via a crafted PDF file. | 1.5% | — |
| CVE-2017-5033 | MED 4.3 | debian debian_linux Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android failed to correctly propagate CSP restrictions to local scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML pa | 1.5% | — |
| CVE-2015-0599 | MED 4.3 | cisco unified_computing_system The web interface in Cisco Integrated Management Controller in Cisco Unified Computing System (UCS) on C-Series Rack Servers does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspe | 1.5% | — |
| CVE-2014-2147 | MED 4.3 | cisco prime_infrastructure The web interface in Cisco Prime Infrastructure 2.1 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cr | 1.5% | — |
| CVE-2000-0259 | HIGH 7.2 | microsoft terminal_server The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users. | 1.5% | — |
| CVE-2024-21316 | MED 6.1 | microsoft windows_10_1607 Windows Server Key Distribution Service Security Feature Bypass | 1.5% | — |
| CVE-2023-27296 | HIGH 8.8 | apache inlong Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong, you could refer to [1] to know more about this vulnerability. This issue affects Apache InLong: from 1.1.0 th | 1.5% | — |
| CVE-2022-46365 | CRIT 9.1 | apache streampark Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, T | 1.5% | — |
| CVE-2022-41048 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2022-41047 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2022-37978 | HIGH 7.5 | microsoft windows_10 Windows Active Directory Certificate Services Security Feature Bypass | 1.5% | — |
| CVE-2021-36007 | LOW 3.3 | adobe prelude Adobe Prelude version 10.0 (and earlier) are affected by an uninitialized variable vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the | 1.5% | — |
| CVE-2021-29907 | HIGH 8.8 | ibm openpages_with_watson IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary code on the system. IBM X-Force ID: 207633. | 1.5% | — |
| CVE-2021-21999 | HIGH 7.8 | vmware app_volumes VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a | 1.5% | — |
| CVE-2020-1049 | MED 5.4 | microsoft dynamics_365_server A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. This | 1.5% | — |
| CVE-2020-0754 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0753. | 1.5% | — |
| CVE-2020-0656 | MED 5.4 | microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. | 1.5% | — |
| CVE-2025-21332 | MED 4.3 | microsoft windows_10_1507 MapUrlToZone Security Feature Bypass Vulnerability | 1.5% | — |
| CVE-2023-28742 | HIGH 7.2 | f5 big-ip_domain_name_system When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 1.5% | — |
| CVE-2022-27489 | HIGH 7.2 | fortinet fortiextender_firmware A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.0.0 through 7.0.3, 5.3.2, 4.2.4 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests. | 1.5% | — |