56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.793 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-43947 | MED 5.0 | fortinet fortios An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 through 7.2.3 and before 7.0.10, FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 administrative interface allows an attacker with a v | 0.4% | — |
| CVE-2022-42292 | MED 5.0 | nvidia geforce_experience NVIDIA GeForce Experience contains a vulnerability in the NVContainer component, where a user without administrator privileges can create a symbolic link to a file that requires elevated privileges to write to or modify, which may lead to denial of service, e | 0.2% | — |
| CVE-2022-40733 | MED 5.0 | microsoft windows_11_21h2 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafte | 0.8% | — |
| CVE-2022-40732 | MED 5.0 | microsoft windows_11_21h2 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafte | 0.8% | — |
| CVE-2022-3623 | MED 5.0 | debian debian_linux A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function follow_page_pte of the file mm/gup.c of the component BPF. The manipulation leads to race condition. The attack can be launched remot | 0.8% | — |
| CVE-2022-36088 | MED 5.0 | thoughtworks gocd GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately restrict permissions when installing outside of the default location. This could allow a malicious user with local | 0.2% | — |
| CVE-2022-22380 | MED 5.0 | ibm security_verify_privilege_on-premises IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to spoof a trusted entity due to improperly validating certificates. IBM X-Force ID: 221957. | 0.2% | — |
| CVE-2022-0013 | MED 5.0 | paloaltonetworks cortex_xdr_agent A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker to read the contents of arbitrary files on the system with elevated privileges when generating a support file. This issue impacts: Cortex | 0.2% | — |
| CVE-2021-4287 | MED 5.0 | microsoft binwalk A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/binwalk/modules/extractor.py of the component Archive Extraction Handler. The manipulation leads to symlink foll | 1.9% | — |
| CVE-2021-42297 | MED 5.0 | microsoft windows_10_update_assistant Windows 10 Update Assistant Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2021-34485 | MED 5.0 | microsoft .net .NET Core and Visual Studio Information Disclosure Vulnerability | 1.5% | — |
| CVE-2021-32600 | MED 5.0 | fortinet fortios An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information | 0.6% | — |
| CVE-2021-31944 | MED 5.0 | microsoft 3d_viewer 3D Viewer Information Disclosure Vulnerability | 2.8% | — |
| CVE-2021-28450 | MED 5.0 | microsoft sharepoint_foundation Microsoft SharePoint Denial of Service Vulnerability | 2.4% | — |
| CVE-2021-24100 | MED 5.0 | microsoft edge Microsoft Edge for Android Information Disclosure Vulnerability | 2.8% | — |
| CVE-2021-1684 | MED 5.0 | microsoft windows_10 Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software | 1.6% | — |
| CVE-2021-1683 | MED 5.0 | microsoft windows_10 Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software | 1.7% | — |
| CVE-2021-1645 | MED 5.0 | microsoft windows_10 Windows Docker Information Disclosure Vulnerability | 7.3% | — |
| CVE-2021-1517 | MED 5.0 | cisco webex_meetings_online A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to bypass security protections. This vulnerability is due to unsafe handling of shared content within the mul | 0.8% | — |
| CVE-2021-1464 | MED 5.0 | cisco catalyst_sd-wan_manager A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain restricted access to the configuration information of an affected system. This vulnerability exists because the affec | 1.3% | — |
| CVE-2021-0212 | MED 5.0 | juniper contrail_networking An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker able to read files to retrieve administrator credentials stored in plaintext thereby elevating their privileges over the system. This issue af | 0.3% | — |
| CVE-2020-3472 | MED 5.0 | cisco webex_meetings_online A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to access sensitive information. The vulnerability is due to improper access restrictions on users who are added within | 1.1% | — |
| CVE-2020-29010 | MED 5.0 | fortinet fortios An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to read the SSL VPN events log entries of users in other VDOMs by executing "get vpn | 0.6% | — |
| CVE-2020-28974 | MED 5.0 | debian debian_linux A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged information or potentially crash the kernel, aka CID-3c4e0dff2095. This occurs because KD_FONT_OP_COPY in drivers/tty/vt/vt.c can be used fo | 0.5% | — |
| CVE-2020-16950 | MED 5.0 | microsoft sharepoint_server <p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To | 4.2% | — |