57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1542 | HIGH 7.2 | cisco sf220-24_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Con | 1.4% | — |
| CVE-2017-11589 | CRIT 9.8 | cisco residential_gateway_firmware On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is no access control for info.html, wancfg.cmd, rtroutecfg.cmd, arpview.cmd, cpuvi | 1.4% | — |
| CVE-2013-2263 | MED 5.0 | citrix access_gateway Unspecified vulnerability in Citrix Access Gateway Standard Edition 5.0.x before 5.0.4.223524 allows remote attackers to access network resources via unknown attack vectors. | 1.4% | — |
| CVE-2005-3175 | HIGH 7.2 | microsoft windows_2000 Microsoft Windows 2000 before Update Rollup 1 for SP4 allows a local administrator to unlock a computer even if it has been locked by a domain administrator, which allows the local administrator to access the session as the domain administrator. | 1.4% | — |
| CVE-2001-0056 | HIGH 7.5 | cisco broadband_operating_system The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection. | 1.4% | — |
| CVE-1999-1362 | LOW 2.1 | microsoft windows_nt Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters. | 1.4% | — |
| CVE-1999-0415 | HIGH 7.5 | cisco cisco_7xx_routers The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration. | 1.4% | — |
| CVE-2026-25181 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network. | 1.4% | — |
| CVE-2024-31860 | MED 6.5 | apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access. This issue affects Apache Zeppelin: from 0.9.0 before 0 | 1.4% | — |
| CVE-2023-35322 | HIGH 8.8 | microsoft windows_server_2008 Windows Deployment Services Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-35300 | HIGH 8.8 | microsoft windows_10_1507 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2022-41035 | MED 5.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.4% | — |
| CVE-2022-20956 | HIGH 7.1 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-base | 1.4% | — |
| CVE-2022-20622 | HIGH 8.6 | cisco aironet_access_point_software A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) conditi | 1.4% | — |
| CVE-2021-43073 | HIGH 8.8 | fortinet fortiweb A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HT | 1.4% | — |
| CVE-2021-40112 | CRIT 10.0 | cisco catalyst_pon_switch_cgp-ont-1p_firmware Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a de | 1.4% | — |
| CVE-2021-1402 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vuln | 1.4% | — |
| CVE-2020-5873 | HIGH 7.2 | f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.1-11.6.5 and BIG-IQ 5.2.0-7.1.0, a user associated with the Resource Administrator role who has access to the secure copy (scp) utility but does not have access to Advanced Shel | 1.4% | — |
| CVE-2020-3945 | HIGH 7.5 | vmware vrealize_operations vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenti | 1.4% | — |
| CVE-2016-9224 | MED 6.5 | cisco jabber_guest A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts. More Information: CSCvc31635. Known Affected Releases: 10.6(9). Known Fixed Releases: 11.0(0). | 1.4% | — |
| CVE-2014-3377 | MED 4.0 | cisco ios_xr snmpd in Cisco IOS XR 5.1 and earlier allows remote authenticated users to cause a denial of service (process reload) via a malformed SNMPv2 packet, aka Bug ID CSCun67791. | 1.4% | — |
| CVE-2026-65663 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.4% | — |
| CVE-2026-65658 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.4% | — |
| CVE-2022-0812 | MED 4.3 | linux linux_kernel An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c in the Linux Kernel. This flaw allows an attacker with normal user privileges to leak kernel information. | 1.4% | — |
| CVE-2021-1279 | HIGH 8.6 | cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | 1.4% | — |