57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-3794 | HIGH 8.8 | cisco webex_meetings_server A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against an administrative user. More Information: CSCuz03317. Known Affected Releases: 2.6. Known Fixed Release | 1.1% | — |
| CVE-2016-1411 | MED 5.9 | cisco content_security_management_appliance A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Management Security Appliance (SMA) could allow an unauthenticated, remote attacker to imperso | 1.1% | — |
| CVE-2014-1739 | LOW 2.1 | canonical ubuntu_linux The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging /dev/media0 read a | 1.1% | — |
| CVE-2025-25002 | MED 6.8 | microsoft azure_local_cluster Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network. | 1.1% | — |
| CVE-2024-48890 | MED 6.6 | fortinet fortisoar_imap_connector An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specific | 1.1% | — |
| CVE-2024-26247 | MED 4.7 | microsoft edge Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2024-26177 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 1.1% | — |
| CVE-2022-33674 | HIGH 8.3 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-42301 | LOW 3.3 | microsoft azure_rtos Azure RTOS Information Disclosure Vulnerability | 1.1% | — |
| CVE-2020-29661 | HIGH 7.8 | broadcom fabric_operating_system A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b. | 1.1% | — |
| CVE-2018-15390 | MED 6.8 | cisco secure_firewall_threat_defense A vulnerability in the FTP inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists beca | 1.1% | — |
| CVE-2016-6363 | MED 6.5 | cisco aironet_access_point_software The rate-limit feature in the 802.11 protocol implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device reload) via crafted 802.11 frames, | 1.1% | — |
| CVE-2016-6361 | MED 6.5 | cisco aironet_access_point_software The Aggregated MAC Protocol Data Unit (AMPDU) implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device reload) via a crafted AMPDU header | 1.1% | — |
| CVE-2016-1441 | HIGH 8.2 | cisco cloud_network_automation_provisioner Cisco Cloud Network Automation Provisioner (CNAP) 1.0(0) in Cisco Configuration Assistant (CCA) allows remote attackers to bypass intended filesystem and administrative-endpoint restrictions via GET API calls, aka Bug ID CSCuy77145. | 1.1% | — |
| CVE-2023-29183 | HIGH 8.0 | fortinet fortios An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6. | 1.1% | — |
| CVE-2022-41742 | HIGH 7.1 | debian debian_linux NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to ca | 1.1% | — |
| CVE-2021-41014 | HIGH 7.5 | fortinet fortiweb A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets | 1.1% | — |
| CVE-2020-3973 | HIGH 8.8 | arista velocloud_orchestrator The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged. | 1.1% | — |
| CVE-2017-6158 | MED 6.5 | f5 big-ip_access_policy_manager In F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.1, 11.5.1-11.5.5, or 11.2.1 there is a vulnerability in TMM related to handling of invalid IP addresses. | 1.1% | — |
| CVE-2012-4116 | MED 4.3 | cisco unified_computing_system The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allows remote attackers to obtain sensitive information, and consequently complete the authentication process for a server connection, by sniffi | 1.1% | — |
| CVE-2026-20094 | HIGH 8.8 | cisco unified_computing_system A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulne | 1.1% | — |
| CVE-2025-55243 | HIGH 7.5 | microsoft officeplus Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network. | 1.1% | — |
| CVE-2023-35297 | HIGH 8.1 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-46870 | MED 5.4 | apache zeppelin An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2. Users are | 1.1% | — |
| CVE-2021-22984 | MED 6.1 | f5 big-ip_advanced_web_application_firewall On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x before 13.1.3.4, 12.1.x before 12.1.5.2, and 11.6.x before 11.6.5.2, when receiving a unauthenticated client request with a maliciously crafte | 1.1% | — |