57.361 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.361 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-0671 | MED 5.8 | cisco mediasense Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, aka Bug ID CSCum16749. | 2.3% | — |
| CVE-2014-0460 | MED 5.8 | canonical ubuntu_linux Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vectors related to JNDI. | 4.3% | — |
| CVE-2014-0116 | MED 5.8 | apache struts CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted requ | 6.6% | — |
| CVE-2013-6971 | MED 5.8 | cisco webex_training_center Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul57140. | 2.1% | — |
| CVE-2013-6967 | MED 5.8 | cisco webex_sales_center Open redirect vulnerability in the mobile-browser subsystem in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul36020. | 2.1% | — |
| CVE-2013-6966 | MED 5.8 | cisco webex_training_center Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul36031. | 2.1% | — |
| CVE-2013-6959 | MED 5.8 | cisco webex_sales_center Open redirect vulnerability in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul25557. | 2.1% | — |
| CVE-2013-6798 | MED 5.8 | blackberry blackberry_link BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not properly determine the user account for execution of Peer Manager in certain situations involving successive logins with different accounts, which allows context-dependen | 1.9% | — |
| CVE-2013-6077 | MED 5.8 | citrix xendesktop Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass intended restrictions. | 1.7% | — |
| CVE-2013-4390 | MED 5.8 | apache sling Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Sling allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in th | 3.1% | — |
| CVE-2013-4345 | MED 5.8 | fedoraproject fedora Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple requests for small amounts of data, leading to | 3.2% | — |
| CVE-2013-4310 | MED 5.8 | apache struts Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix. | 7.5% | — |
| CVE-2013-4286 | MED 5.8 | apache tomcat Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incorrect identification of | 16.8% | — |
| CVE-2013-3446 | MED 5.8 | cisco digital_media_manager Open redirect vulnerability in the login page in Cisco Digital Media Manager (DMM) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCub23849. | 1.1% | — |
| CVE-2013-2248 | MED 5.8 | apache struts Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix. | 94.7% | — |
| CVE-2013-2155 | MED 5.8 | apache xml_security_for_c\+\+ Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted leng | 5.8% | — |
| CVE-2013-2070 | MED 5.8 | debian debian_linux http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process me | 11.9% | — |
| CVE-2013-1909 | MED 5.8 | apache qpid The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an | 1.6% | — |
| CVE-2013-1299 | MED 5.8 | microsoft modern_mail Microsoft Windows Modern Mail allows remote attackers to spoof link targets via a crafted HTML e-mail message. | 9.5% | — |
| CVE-2013-1212 | MED 5.8 | cisco nexus_1000v The SSL functionality in Cisco NX-OS on the Nexus 1000V does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof servers, and intercept or modify Virtual Supervisor Module (VSM) to VMware vCenter communication, via a craft | 0.7% | — |
| CVE-2013-1208 | MED 5.8 | cisco nx-os The encryption functionality in Cisco NX-OS on the Nexus 1000V does not properly handle Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication, which allows remote attackers to intercept or modify network traffic by leveraging certain L | 0.9% | — |
| CVE-2013-1124 | MED 5.8 | cisco network_admission_control The Cisco Network Admission Control (NAC) agent on Mac OS X does not verify the X.509 certificate of an Identity Services Engine (ISE) server during an SSL session, which allows man-in-the-middle attackers to spoof ISE servers via an arbitrary certificate, aka | 0.5% | — |
| CVE-2013-0253 | MED 5.8 | apache maven The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack. | 1.6% | — |
| CVE-2013-0149 | MED 5.8 | cisco asa_5500 The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before perf | 2.5% | — |
| CVE-2013-0013 | MED 5.8 | microsoft windows_7 The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to c | 6.4% | — |