58.165 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-24461 | HIGH 7.4 | f5 big-ip_access_policy_manager An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow an attacker to impersonate a BIG-IP APM system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.3% | — |
| CVE-2023-2316 | HIGH 7.4 | typora typora Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/<absolute-path>". This vulnerability can be exploited if a user opens a malicious ma | 0.7% | — |
| CVE-2023-21820 | HIGH 7.4 | microsoft windows_10 Windows Distributed File System (DFS) Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-21526 | HIGH 7.4 | microsoft windows_10_1507 Windows Netlogon Information Disclosure Vulnerability | 1.1% | — |
| CVE-2023-20185 | HIGH 7.4 | cisco nx-os A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic. This vulnerability is due to an iss | 0.3% | — |
| CVE-2023-20169 | HIGH 7.4 | cisco nx-os A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker | 0.3% | — |
| CVE-2023-20112 | HIGH 7.4 | cisco business_150ax_firmware A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain parameters within 802.11 f | 0.3% | — |
| CVE-2023-20089 | HIGH 7.4 | cisco nx-os A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to cause a memory leak, which could result in an | 0.3% | — |
| CVE-2023-20067 | HIGH 7.4 | cisco ios_xe A vulnerability in the HTTP-based client profiling feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is | 0.3% | — |
| CVE-2022-41042 | HIGH 7.4 | microsoft visual_studio_code Visual Studio Code Information Disclosure Vulnerability | 2.0% | — |
| CVE-2022-40678 | HIGH 7.4 | fortinet fortinac An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow a local attacker with database access to | 0.1% | — |
| CVE-2022-30209 | HIGH 7.4 | microsoft windows_10 Windows IIS Server Elevation of Privilege Vulnerability | 2.5% | — |
| CVE-2022-30203 | HIGH 7.4 | microsoft windows_10 Windows Boot Manager Security Feature Bypass Vulnerability | 1.5% | — |
| CVE-2022-26913 | HIGH 7.4 | microsoft windows_10 Windows Authentication Information Disclosure Vulnerability | 2.4% | — |
| CVE-2022-26071 | HIGH 7.4 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a flaw in the way reply ICMP packets are limited in the Traffic Manage | 1.1% | — |
| CVE-2022-22190 | HIGH 7.4 | juniper paragon_active_assurance_control_center An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to leverage a crafted URL to generate PDF reports, potentially containing sensitive configuration information. A feature | 1.0% | — |
| CVE-2022-22176 | HIGH 7.4 | juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker sending a malformed DHCP packet to cause a crash of jdhcpd and thereby a Denial | 0.4% | — |
| CVE-2022-22163 | HIGH 7.4 | juniper junos An Improper Input Validation vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a crash of jdhcpd and thereby a Denial of Service (DoS). If a device is configured as DHCPv6 local | 0.4% | — |
| CVE-2022-20945 | HIGH 7.4 | cisco catalyst_9800-40_firmware A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insu | 0.4% | — |
| CVE-2022-20915 | HIGH 7.4 | cisco ios_xe A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability | 0.3% | — |
| CVE-2022-20866 | HIGH 7.4 | cisco adaptive_security_appliance_software A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve an RSA private key. This vulnerability | 17.4% | — |
| CVE-2022-20860 | HIGH 7.4 | cisco nexus_dashboard A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information. This vulnerability exists because SSL server certificates | 0.5% | — |
| CVE-2022-20853 | HIGH 7.4 | cisco telepresence_video_communication_server A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insuffi | 0.6% | — |
| CVE-2022-20817 | HIGH 7.4 | cisco ata_187_analog_telephone_adapter_firmware A vulnerability in Cisco Unified IP Phones could allow an unauthenticated, remote attacker to impersonate another user's phone if the Cisco Unified Communications Manager (CUCM) is in secure mode. This vulnerability is due to improper key generation during the | 1.2% | — |
| CVE-2022-20814 | HIGH 7.4 | cisco telepresence_video_communication_server A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to a lack of validation | 0.9% | — |