56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-33768 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2021-33754 | HIGH 8.0 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-33746 | HIGH 8.0 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-31373 | HIGH 8.0 | juniper junos A persistent Cross-Site Scripting (XSS) vulnerability in Juniper Networks Junos OS on SRX Series, J-Web interface may allow a remote authenticated user to inject persistent and malicious scripts. An attacker can exploit this vulnerability to steal sensitive da | 0.8% | — |
| CVE-2021-31355 | HIGH 8.0 | juniper junos A persistent cross-site scripting (XSS) vulnerability in the captive portal graphical user interface of Juniper Networks Junos OS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administrat | 0.8% | — |
| CVE-2021-3052 | HIGH 8.0 | paloaltonetworks pan-os A reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface enables an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performs arbitrar | 0.6% | — |
| CVE-2021-1726 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 2.0% | — |
| CVE-2021-1719 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2021-1718 | HIGH 8.0 | microsoft sharepoint_foundation Microsoft SharePoint Server Tampering Vulnerability | 2.6% | — |
| CVE-2021-1712 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2020-7877 | HIGH 8.0 | mastersoft zook_agent A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' command while parsing a crafted OUTERIP value because of missing boundary check. This vulnerability allows the attacker to execute remote arbitra | 0.8% | — |
| CVE-2020-7849 | HIGH 8.0 | uprism curix A vulnerability of uPrism.io CURIX(Video conferecing solution) could allow an unauthenticated attacker to execute arbitrary code. This vulnerability is due to insufficient input(server domain) validation. An attacker could exploit this vulnerability through cr | 1.3% | — |
| CVE-2020-26217 | HIGH 8.0 | apache activemq XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XSt | 85.0% | — |
| CVE-2020-17115 | HIGH 8.0 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 2.5% | — |
| CVE-2020-17016 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 3.2% | — |
| CVE-2020-1552 | HIGH 8.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnera | 2.4% | — |
| CVE-2020-15261 | HIGH 8.0 | veyon veyon On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally authenticated users with administrative privileges to run malicious executables with LocalSystem privileges. Since Veyon users (both students an | 11.3% | — |
| CVE-2020-1022 | HIGH 8.0 | microsoft dynamics_365_business_central A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. | 6.8% | — |
| CVE-2020-0905 | HIGH 8.0 | microsoft dynamics_365_business_central An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. | 10.8% | — |
| CVE-2020-0655 | HIGH 8.0 | microsoft windows_10 A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'. | 65.7% | — |
| CVE-2019-18909 | HIGH 8.0 | hp thinpro The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges. | 2.2% | — |
| CVE-2019-1647 | HIGH 8.0 | cisco sd-wan A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to other vSmart containers. The vulnerability is due to an insecure default configuration of the affected | 0.8% | — |
| CVE-2019-1583 | HIGH 8.0 | paloaltonetworks twistlock Escalation of privilege vulnerability in the Palo Alto Networks Twistlock console 19.07.358 and earlier allows a Twistlock user with Operator capabilities to escalate privileges to that of another user. Active interaction with an affected component is required | 1.0% | — |
| CVE-2019-15252 | HIGH 8.0 | cisco spa112_firmware Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to th | 0.6% | — |
| CVE-2019-15251 | HIGH 8.0 | cisco spa112_firmware Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to th | 0.6% | — |