57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-6598 | MED 4.3 | f5 big-ip_access_policy_manager In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or Enterprise Manager 3.1.1, malformed requests to the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, may lead to di | 1.0% | — |
| CVE-2018-15325 | MED 4.3 | f5 big-ip_access_policy_manager In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, iControl and TMSH usage by authenticated users may leak a small amount of memory when executing commands | 1.0% | — |
| CVE-2014-0724 | MED 4.0 | cisco unified_communications_manager The bulk administration interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to bypass authentication and read arbitrary files by using an unspecified prompt, aka Bug ID CSCum05340. | 1.0% | — |
| CVE-2024-20684 | MED 6.5 | microsoft windows_11_21h2 Windows Hyper-V Denial of Service Vulnerability | 1.0% | — |
| CVE-2023-29486 | CRIT 9.8 | heimdalsecurity thor An issue was discovered in Heimdal Thor agent versions 3.4.2 and before 3.7.0 on Windows, allows attackers to bypass USB access restrictions, execute arbitrary code, and obtain sensitive information via Next-Gen Antivirus component. NOTE: Heimdal argues that t | 1.0% | — |
| CVE-2022-20933 | HIGH 8.6 | cisco meraki_mx100_firmware A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z3 Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due t | 1.0% | — |
| CVE-2021-0248 | CRIT 10.0 | juniper junos This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS allows an attacker to take over any instance of an NFX deployment. This issue is only exploitable through administrative | 1.0% | — |
| CVE-2021-1469 | CRIT 9.9 | cisco jabber Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, | 1.0% | — |
| CVE-2021-1221 | MED 4.1 | cisco webex_meetings A vulnerability in the user interface of Cisco Webex Meetings and Cisco Webex Meetings Server Software could allow an authenticated, remote attacker to inject a hyperlink into a meeting invitation email. The vulnerability is due to insufficient input validatio | 1.0% | — |
| CVE-2020-16895 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash. An attacker who successfully exploited this vulnerability could delete a targeted file leading to an elevated status.</p> <p>To exploit t | 1.0% | — |
| CVE-2020-0984 | HIGH 7.8 | microsoft autoupdate An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka 'Microsoft (MAU) Office Elevation of Privilege Vulnerability'. | 1.0% | — |
| CVE-2020-0861 | HIGH 7.8 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Network Dri | 1.0% | — |
| CVE-2019-1190 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally au | 1.0% | — |
| CVE-2018-0089 | HIGH 7.5 | cisco policy_suite A vulnerability in the Policy and Charging Rules Function (PCRF) of the Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attacks. The | 1.0% | — |
| CVE-2026-47302 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | 1.0% | — |
| CVE-2026-48573 | HIGH 7.9 | microsoft windows_10_1607 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 1.0% | — |
| CVE-2024-38220 | CRIT 9.0 | microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2024-29736 | CRIT 9.1 | apache cxf A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured. | 1.0% | — |
| CVE-2018-0402 | HIGH 8.8 | cisco unified_contact_center_express Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. Cisco Bug IDs: CSCvg70921. | 1.0% | — |
| CVE-2015-4162 | MED 4.0 | paloaltonetworks pan-os XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x before 6.1.4 allows remote authenticated administrators to obtain sensitive information via crafted XML data. | 1.0% | — |
| CVE-2013-3437 | MED 6.5 | cisco unified_operations_manager SQL injection vulnerability in the management application in Cisco Unified Operations Manager allows remote authenticated users to execute arbitrary SQL commands via an entry field, aka Bug ID CSCud80179. | 1.0% | — |
| CVE-2009-4916 | MED 4.0 | cisco asa_5580 Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote authenticated users to cause a denial of service (console hang) via a login action during failover replication, aka Bug ID CSCsq | 1.0% | — |
| CVE-2009-3002 | MED 4.9 | canonical ubuntu_linux The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to the atalk_ge | 1.0% | — |
| CVE-2026-48576 | HIGH 7.9 | microsoft windows_10_1607 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 1.0% | — |
| CVE-2021-47384 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field If driver read tmp value sufficient for (tmp & 0x08) && (!(tmp & 0x80)) && ((tmp & 0x7) == ((tmp >> 4) & | 1.0% | — |