IT
57.613 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.613 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2017-6670 MED 6.1 cisco unified_communications_domain_manager A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue. More Information: CSCvc54813. Known Affected Releases: 8 1.2%
CVE-2017-6604 MED 6.1 cisco unified_computing_system A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability affects the following Cisco products running Cisco IMC 1.2%
CVE-2026-70065 HIGH 7.5 microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-26119 HIGH 8.8 microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. 1.2%
CVE-2020-10866 HIGH 7.5 avast antivirus An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to enumerate the network interfaces and access points from a Low Integrity process via RPC. 1.2%
CVE-2019-12623 MED 4.3 cisco enterprise_network_functions_virtualization_infrastructure A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform file enumeration on an affected system. The vulnerability is due to th 1.2%
CVE-2018-15406 MED 6.1 cisco ucs_director A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vu 1.2%
CVE-2017-0328 MED 4.7 linux linux_kernel An information disclosure vulnerability in the NVIDIA crypto driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product 1.2%
CVE-2013-1120 MED 6.8 cisco unity_express Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCue35910. 1.2%
CVE-2025-27744 HIGH 7.8 microsoft office Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally. 1.2%
CVE-2022-41720 HIGH 7.5 golang go On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example, o 1.2%
CVE-2002-0725 MED 5.5 microsoft windows_2000 NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file. 1.2%
CVE-2021-29779 MED 5.9 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in the middle techniques. IBM X-Force ID: 203033. 1.2%
CVE-2012-4144 MED 4.3 opera opera_browser Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, does not properly escape characters in DOM elements, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted 1.2%
CVE-2026-8666 HIGH 7.7 rapid7 insightconnect_traceroute OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient inpu 1.2%
CVE-2026-8665 HIGH 7.7 rapid7 insightconnect_translate OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command constr 1.2%
CVE-2026-8660 HIGH 7.7 rapid7 insightconnect_ping OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter due to insufficient input validation when constructing shell commands. 1.2%
CVE-2026-8592 HIGH 7.7 rapid7 insightconnect_awk OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processi 1.2%
CVE-2026-32225 HIGH 8.8 microsoft windows_10_1607 Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. 1.2%
CVE-2024-41172 HIGH 7.5 apache cxf In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventual 1.2%
CVE-2021-26892 MED 6.2 microsoft windows_10 Windows Extensible Firmware Interface Security Feature Bypass Vulnerability 1.2%
CVE-2021-1493 HIGH 8.5 cisco adaptive_security_appliance_software A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerabilit 1.2%
CVE-2019-1692 MED 5.3 cisco application_policy_infrastructure_controller A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information. The vulnerability is due to a lack of prop 1.2%
CVE-2018-5528 MED 5.3 f5 big-ip_access_policy_manager Under certain conditions, TMM may restart and produce a core file while processing APM data on BIG-IP 13.0.1 or 13.1.0.4-13.1.0.7. 1.2%
CVE-2017-7216 MED 6.5 paloaltonetworks pan-os The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to obtain sensitive information via unspecified request parameters. 1.2%