57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-1401 | MED 6.1 | cisco unified_computing_system_central_software Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy91250. | 1.0% | — |
| CVE-2016-1377 | MED 6.1 | cisco unity_connection Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCus21776. | 1.0% | — |
| CVE-2016-1318 | MED 6.1 | cisco application_policy_infrastructure_controller_enterprise_module Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data, aka Bug ID CSCux15489. | 1.0% | — |
| CVE-2016-1309 | MED 6.1 | cisco webex_meetings_server Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meetings Server 2.5.1.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy01843. | 1.0% | — |
| CVE-2016-1305 | MED 6.1 | cisco application_policy_infrastructure_controller_enterprise_module Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML entities, aka Bug ID CSCux15511. | 1.0% | — |
| CVE-2016-1311 | MED 6.1 | cisco jabber_guest Cross-site scripting (XSS) vulnerability in the management interface in Cisco Jabber Guest Server 10.6(8) allows remote attackers to inject arbitrary web script or HTML via the host tag parameter, aka Bug ID CSCuy08224. | 1.0% | — |
| CVE-2016-1304 | MED 6.1 | cisco unity_connection Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 10.5(2.3009) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCux82596. | 1.0% | — |
| CVE-2015-6337 | MED 6.1 | cisco application_policy_infrastructure_controller_enterprise_module Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0.10 allows remote attackers to inject arbitrary web script or HTML via a crafted hostname in an SNMP response, aka Bug ID CSCuw47238. | 1.0% | — |
| CVE-2014-8727 | MED 6.2 | f5 big-ip_local_traffic_manager Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrator" or "Administrator" role to enumerate and delete arbitrary files via a .. (dot dot) in the name parameter to (1) tmui/Control/jspmap/tmui | 1.0% | — |
| CVE-2026-56170 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 1.0% | — |
| CVE-2024-38048 | MED 6.5 | microsoft windows_10_1507 Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability | 1.0% | — |
| CVE-2024-38027 | MED 6.5 | microsoft windows_10_1507 Windows Line Printer Daemon Service Denial of Service Vulnerability | 1.0% | — |
| CVE-2024-31863 | MED 5.3 | apache zeppelin Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue. | 1.0% | — |
| CVE-2021-31378 | MED 6.8 | juniper junos In broadband environments, including but not limited to Enhanced Subscriber Management, (CHAP, PPP, DHCP, etc.), on Juniper Networks Junos OS devices where RADIUS servers are configured for managing subscriber access and a subscriber is logged in and then requ | 1.0% | — |
| CVE-2021-0299 | HIGH 7.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in the processing of a transit or directly received malformed IPv6 packet in Juniper Networks Junos OS results in a kernel crash, causing the device to restart, leading to a Denial of Service (DoS). | 1.0% | — |
| CVE-2021-3053 | HIGH 7.5 | paloaltonetworks pan-os An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to crash. Re | 1.0% | — |
| CVE-2021-0291 | MED 6.5 | juniper junos An Exposure of System Data vulnerability in Juniper Networks Junos OS and Junos OS Evolved, where a sensitive system-level resource is not being sufficiently protected, allows a network-based unauthenticated attacker to send specific traffic which partially re | 1.0% | — |
| CVE-2021-1704 | HIGH 7.3 | microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2018-15433 | MED 4.3 | cisco prime_infrastructure A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker | 1.0% | — |
| CVE-2018-15432 | MED 4.3 | cisco prime_infrastructure A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker | 1.0% | — |
| CVE-2017-14954 | MED 5.5 | linux linux_kernel The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in unintended cases, which allows local users to obtain sensitive information, and bypass the KASLR protection mechanism, via a crafted system call. | 1.0% | — |
| CVE-2025-29956 | MED 5.4 | microsoft windows_10_1507 Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2023-30575 | MED 6.5 | apache guacamole Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol handshake, potentially allowing an attacker to inject Guacamole instructions during the handshake through specially-crafted data. | 1.0% | — |
| CVE-2023-26022 | MED 5.9 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash when an Out of Memory occurs using the DBMS_OUTPUT module. IBM X-Force ID: 247868. | 1.0% | — |
| CVE-2020-1530 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Remote Access improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application | 1.0% | — |