57.469 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.469 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-45031 | MED 6.1 | apache syncope When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored XSS payloads which would trigger for other users during ordinary usage of the application. XSS payloads could al | 0.7% | — |
| CVE-2024-44088 | MED 6.1 | apache geode Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a logged-in user into clicking a specially-crafted link to execute code on the returned page, which could lead t | 0.6% | — |
| CVE-2024-42423 | MED 6.1 | citrix workspace Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existi | 0.2% | — |
| CVE-2024-41937 | MED 6.1 | apache airflow Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web s | 1.7% | — |
| CVE-2024-41177 | MED 6.1 | apache zeppelin Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue. | 0.6% | — |
| CVE-2024-3841 | MED 6.1 | fedoraproject fedora Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium) | 0.7% | — |
| CVE-2024-38208 | MED 6.1 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 0.4% | — |
| CVE-2024-38156 | MED 6.1 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.4% | — |
| CVE-2024-37304 | MED 6.1 | microsoft nugetgallery NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately | 0.7% | — |
| CVE-2024-33604 | MED 6.1 | f5 big-ip_access_policy_manager A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Tec | 0.3% | — |
| CVE-2024-31868 | MED 6.1 | apache zeppelin Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version | 1.3% | — |
| CVE-2024-30059 | MED 6.1 | microsoft intune_mobile_application_management Microsoft Intune for Android Mobile Application Management Tampering Vulnerability | 0.6% | — |
| CVE-2024-27136 | MED 6.1 | apache jspwiki XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later. | 60.8% | — |
| CVE-2024-25709 | MED 6.1 | esri portal_for_arcgis There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may allow a remote, authenticated attacker to create a crafted link that can be saved as a new location when moving an existing item, which could | 0.4% | — |
| CVE-2024-25698 | MED 6.1 | esri portal_for_arcgis There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute a | 0.4% | — |
| CVE-2024-24915 | MED 6.1 | checkpoint smartconsole Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them. | 0.2% | — |
| CVE-2024-23664 | MED 6.1 | fortinet fortiauthenticator A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL. | 0.3% | — |
| CVE-2024-21757 | MED 6.1 | fortinet fortianalyzer A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4 | 0.2% | — |
| CVE-2024-21316 | MED 6.1 | microsoft windows_10_1607 Windows Server Key Distribution Service Security Feature Bypass | 1.5% | — |
| CVE-2024-20665 | MED 6.1 | microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-20538 | MED 6.1 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not suffic | 0.3% | — |
| CVE-2024-20530 | MED 6.1 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not proper | 0.3% | — |
| CVE-2024-20525 | MED 6.1 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not proper | 0.3% | — |
| CVE-2024-20512 | MED 6.1 | cisco unified_contact_center_management_portal A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. | 0.3% | — |
| CVE-2024-20511 | MED 6.1 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-s | 0.3% | — |