56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.571 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-20275 | MED 4.1 | cisco adaptive_security_appliance_software A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address. Thi | 0.4% | — |
| CVE-2023-0005 | MED 4.1 | paloaltonetworks pan-os A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys. | 0.3% | — |
| CVE-2022-45859 | MED 4.1 | fortinet fortinac An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions, 8.7.0 all versions may allow a local attacker with system access to retrieve users' passwords. | 0.1% | — |
| CVE-2022-29839 | MED 4.1 | westerndigital my_cloud_os Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This issue affe | 0.1% | — |
| CVE-2022-24466 | MED 4.1 | microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2022-20805 | MED 4.1 | cisco umbrella_secure_web_gateway A vulnerability in the automatic decryption process in Cisco Umbrella Secure Web Gateway (SWG) could allow an authenticated, adjacent attacker to bypass the SSL decryption and content filtering policies on an affected system. This vulnerability is due to how t | 0.2% | — |
| CVE-2022-1974 | MED 4.1 | linux linux_kernel A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject creation and delete. This vulnerability allows a local attacker with CAP_NET_ADMIN privilege to leak kernel information. | 0.1% | — |
| CVE-2022-0022 | MED 4.1 | paloaltonetworks pan-os Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator and local user accounts are not created with a sufficient level of computational effort, which allows for password cracking attacks on acco | 0.1% | — |
| CVE-2021-47534 | MED 4.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/vc4: kms: Add missing drm_crtc_commit_put Commit 9ec03d7f1ed3 ("drm/vc4: kms: Wait on previous FIFO users before a commit") introduced a global state for the HVS, with each FIFO storing | 0.2% | — |
| CVE-2021-44166 | MED 4.1 | fortinet fortitoken_mobile An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and below may allow a remote attacker having already obtained a user's password to access the protected system during the 2FA procedure, even th | 0.6% | — |
| CVE-2021-4001 | MED 4.1 | linux linux_kernel A race condition was found in the Linux kernel's ebpf verifier between bpf_map_update_elem and bpf_map_freeze due to a missing lock in kernel/bpf/syscall.c. In this flaw, a local user with a special privilege (cap_sys_admin or cap_bpf) can modify the frozen ma | 0.2% | — |
| CVE-2021-36191 | MED 4.1 | fortinet fortiweb A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers | 0.5% | — |
| CVE-2021-36175 | MED 4.1 | fortinet fortiweb An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below may allow a remote authenticated attacker to inject malicious script/tags via the name/description/comments parameter of various sections of | 0.6% | — |
| CVE-2021-34400 | MED 4.1 | nvidia dgx-1_p100 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed memory, which may lead to information disclosure. | 0.2% | — |
| CVE-2021-34399 | MED 4.1 | nvidia dgx-1_p100 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed registers, which may lead to information disclosure. | 0.2% | — |
| CVE-2021-31171 | MED 4.1 | microsoft sharepoint_foundation Microsoft SharePoint Information Disclosure Vulnerability | 0.6% | — |
| CVE-2021-23219 | MED 4.1 | nvidia dgx-1_p100 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to info | 0.2% | — |
| CVE-2021-1221 | MED 4.1 | cisco webex_meetings A vulnerability in the user interface of Cisco Webex Meetings and Cisco Webex Meetings Server Software could allow an authenticated, remote attacker to inject a hyperlink into a meeting invitation email. The vulnerability is due to insufficient input validatio | 1.0% | — |
| CVE-2021-1125 | MED 4.1 | nvidia dgx-1_p100 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to corrupt program data. | 0.2% | — |
| CVE-2021-1105 | MED 4.1 | nvidia dgx-1_p100 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access debug registers during runtime, which may lead to information disclosure. | 0.2% | — |
| CVE-2021-1088 | MED 4.1 | nvidia dgx-1_p100 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to utilize debug mechanisms with insufficient access control, which may lead to information disclosure. | 0.2% | — |
| CVE-2020-3502 | MED 4.1 | cisco webex_meetings Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters r | 1.0% | — |
| CVE-2020-3501 | MED 4.1 | cisco webex_meetings Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters r | 1.0% | — |
| CVE-2020-26080 | MED 4.1 | cisco iot_field_network_director A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system. The vulnerability is due to improper d | 0.7% | — |
| CVE-2020-25656 | MED 4.1 | debian debian_linux A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is | 0.4% | — |