56.571 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.571 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-23395 | LOW 3.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 0.6% | — |
| CVE-2022-43906 | LOW 3.1 | ibm security_guardium IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 240897. | 0.4% | — |
| CVE-2022-43573 | LOW 3.1 | ibm robotic_process_automation IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modifier of platform level objects. IBM X-Force ID: 238678. | 0.5% | — |
| CVE-2022-3649 | LOW 3.1 | debian debian_linux A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It is possible to launch the attack remotel | 0.8% | — |
| CVE-2022-3646 | LOW 3.1 | debian debian_linux A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function nilfs_attach_log_writer of the file fs/nilfs2/segment.c of the component BPF. The manipulation leads to memory leak. The attack may be initiat | 0.9% | — |
| CVE-2022-3630 | LOW 3.1 | linux linux_kernel A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects some unknown processing of the file fs/fscache/cookie.c of the component IPsec. The manipulation leads to memory leak. It is recommended to apply a patch to fix thi | 0.3% | — |
| CVE-2022-29147 | LOW 3.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.6% | — |
| CVE-2022-1389 | LOW 3.1 | f5 big-ip_access_policy_manager On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site request forgery (CSRF) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This vulnerability allows an attacker to | 0.3% | — |
| CVE-2021-43220 | LOW 3.1 | microsoft edge_ios Microsoft Edge for iOS Spoofing Vulnerability | 1.1% | — |
| CVE-2021-42308 | LOW 3.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.1% | — |
| CVE-2021-36181 | LOW 3.1 | fortinet fortiportal A concurrent execution using shared resource with improper Synchronization vulnerability ('Race Condition') in the customer database interface of FortiPortal before 6.0.6 may allow an authenticated, low-privilege user to bring the underlying database data into | 0.4% | — |
| CVE-2021-32792 | LOW 3.1 | fedoraproject fedora mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is an XSS vuln | 1.5% | — |
| CVE-2021-32719 | LOW 3.1 | vmware rabbitmq RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> | 1.4% | — |
| CVE-2021-32718 | LOW 3.1 | vmware rabbitmq RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper `<script>` tag sanitization, potentially a | 1.4% | — |
| CVE-2020-5928 | LOW 3.1 | f5 big-ip_application_security_manager In versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, BIG-IP ASM Configuration utility CSRF protection token can be reused multiple times. | 0.2% | — |
| CVE-2020-1195 | LOW 3.1 | microsoft edge An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input. An attacker who successfully exploited this vulnerability could write files to arbitrary locations and gain elevated privi | 2.5% | — |
| CVE-2019-1866 | LOW 3.1 | cisco webex_business_suite_39 Cisco Webex Business Suite before 39.1.0 contains a vulnerability that could allow an unauthenticated, remote attacker to affect the integrity of the application. The vulnerability is due to improper validation of host header values. An attacker with a privile | 0.3% | — |
| CVE-2018-8482 | LOW 3.1 | microsoft windows_10 An information disclosure vulnerability exists when Windows Media Player improperly discloses file information, aka "Windows Media Player Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008 | 5.1% | — |
| CVE-2018-8481 | LOW 3.1 | microsoft windows_10 An information disclosure vulnerability exists when Windows Media Player improperly discloses file information, aka "Windows Media Player Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008 | 5.1% | — |
| CVE-2018-8370 | LOW 3.1 | microsoft edge A information disclosure vulnerability exists when WebAudio Library improperly handles audio requests, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. | 4.6% | — |
| CVE-2018-8366 | LOW 3.1 | microsoft edge An information disclosure vulnerability exists when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. | 5.0% | — |
| CVE-2018-16968 | LOW 3.1 | citrix sharefile_storagezones_controller Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal. | 1.1% | — |
| CVE-2018-0878 | LOW 3.1 | microsoft windows_10 Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an informatio | 21.5% | — |
| CVE-2018-0763 | LOW 3.1 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703 and 1709 allows information disclosure, due to how Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0839. | 4.7% | — |
| CVE-2017-11874 | LOW 3.1 | microsoft chakracore Microsoft Edge in Microsoft Windows 10 1703, 1709, Windows Server, version 1709, and ChakraCore allows an attacker to bypass Control Flow Guard (CFG) to run arbitrary code on a target system, due to how Microsoft Edge handles accessing memory in code compiled | 4.0% | — |