57.479 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-20644 | MED 6.1 | cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali | 0.8% | — |
| CVE-2022-20643 | MED 6.1 | cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali | 0.8% | — |
| CVE-2022-20642 | MED 6.1 | cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali | 0.8% | — |
| CVE-2022-20641 | MED 6.1 | cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali | 0.8% | — |
| CVE-2022-20640 | MED 6.1 | cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali | 0.8% | — |
| CVE-2022-20639 | MED 6.1 | cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali | 0.8% | — |
| CVE-2022-20638 | MED 6.1 | cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali | 0.8% | — |
| CVE-2022-20637 | MED 6.1 | cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali | 0.8% | — |
| CVE-2022-20636 | MED 6.1 | cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali | 0.8% | — |
| CVE-2022-20635 | MED 6.1 | cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali | 0.8% | — |
| CVE-2022-20632 | MED 6.1 | cisco enterprise_chat_and_email A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. The vulnerability exists because the web-based management i | 0.5% | — |
| CVE-2022-20631 | MED 6.1 | cisco enterprise_chat_and_email A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. The vulnerability exists because the web-based management i | 0.5% | — |
| CVE-2022-1508 | MED 6.1 | linux linux_kernel An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This flaw allows a local user to read some memory out of bounds. | 0.2% | — |
| CVE-2022-0018 | MED 6.1 | paloaltonetworks globalprotect An information exposure vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows and MacOS where the credentials of the local user account are sent to the GlobalProtect portal when the Single Sign-On feature is enabled in the GlobalProtect p | 0.7% | — |
| CVE-2022-0012 | MED 6.1 | paloaltonetworks cortex_xdr_agent An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables a local user to delete arbitrary system files and impact the system integrity or cause a denial of service conditio | 0.2% | — |
| CVE-2021-45229 | MED 6.1 | apache airflow It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below. | 2.6% | — |
| CVE-2021-44791 | MED 6.1 | apache druid In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks. | 2.1% | — |
| CVE-2021-44201 | MED 6.1 | acronis cyber_protect Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035 | 0.6% | — |
| CVE-2021-43081 | MED 6.1 | fortinet fortios An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may | 0.9% | — |
| CVE-2021-43063 | MED 6.1 | fortinet fortiweb A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET | 0.9% | — |
| CVE-2021-43062 | MED 6.1 | fortinet fortimail A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or com | 12.9% | — |
| CVE-2021-42357 | MED 6.1 | apache knox When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially crafted request parameter could be used to redirect the user to a page controlled by a | 2.6% | — |
| CVE-2021-41368 | MED 6.1 | microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability | 4.9% | — |
| CVE-2021-41015 | MED 6.1 | fortinet fortiweb A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler | 0.8% | — |
| CVE-2021-40776 | MED 6.1 | adobe lightroom Adobe Lightroom Classic 10.3 (and earlier) are affected by a privilege escalation vulnerability in the Offline Lightroom Classic installer. An authenticated attacker could leverage this vulnerability to escalate privileges. User interaction is required before | 0.5% | — |