IT
57.538 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.538 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-43286 CRIT 9.8 f5 njs Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c. 1.0%
CVE-2022-22177 MED 5.3 juniper junos A release of illegal memory vulnerability in the snmpd daemon of Juniper Networks Junos OS, Junos OS Evolved allows an attacker to halt the snmpd daemon causing a sustained Denial of Service (DoS) to the service until it is manually restarted. This issue impac 1.0%
CVE-2021-24006 MED 6.3 fortinet fortimanager An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL. 1.0%
CVE-2021-34491 MED 5.5 microsoft windows_10 Win32k Information Disclosure Vulnerability 1.0%
CVE-2021-1417 CRIT 9.9 cisco jabber Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, 1.0%
CVE-2020-16877 HIGH 7.1 microsoft windows_10 <p>An elevation of privilege vulnerability exists when Microsoft Windows improperly handles reparse points. An attacker who successfully exploited this vulnerability could overwrite or delete a targeted file that would normally require elevated permissions.</p 1.0%
CVE-2017-3869 MED 5.4 cisco prime_infrastructure An API Credentials Management vulnerability in the APIs for Cisco Prime Infrastructure could allow an authenticated, remote attacker to access an API that should be restricted to a privileged user. The attacker needs to have valid credentials. More Information 1.0%
CVE-2014-3823 MED 4.3 juniper junos_pulse_secure_access_service The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 8.0 before 8.0r1, 7.4 before 7.4r5, and 7.1 before 7.1r18 allows remote attackers to conduct clickjacking attacks via unspecified vectors. 1.0%
CVE-2014-2193 MED 4.3 cisco unified_web_and_e-mail_interaction_manager Cisco Unified Web and E-Mail Interaction Manager places session identifiers in GET requests, which allows remote attackers to inject conversation text by obtaining a valid identifier, aka Bug ID CSCuj43084. 1.0%
CVE-2013-3401 MED 4.3 cisco telepresence_tc_software The SIP implementation in Cisco TelePresence TC Software allows remote attackers to trigger unintended use of NOTIFY messages via unspecified vectors, aka Bug ID CSCud96080. 1.0%
CVE-2013-3376 MED 4.3 cisco video_surveillance_operations_manager Open redirect vulnerability in the help page in Cisco Video Surveillance Operations Manager allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCty74490. 1.0%
CVE-2011-3649 LOW 2.6 mozilla firefox Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by in 1.0%
CVE-2026-58281 HIGH 8.3 microsoft edge_chromium Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2024-36912 CRIT 9.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Track decrypted status in vmbus_gpadl In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an err 1.0%
CVE-2023-25504 MED 4.9 apache superset A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery attacks and query internal resources on behalf of the server where Superset is d 1.0%
CVE-2022-35639 HIGH 7.5 ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cause the server to become unresponsive. IBM X-Force ID: 230932. 1.0%
CVE-2021-26884 MED 5.5 microsoft windows_10 Windows Media Photo Codec Information Disclosure Vulnerability 1.0%
CVE-2021-26869 MED 5.5 microsoft windows_10 Windows ActiveX Installer Service Information Disclosure Vulnerability 1.0%
CVE-2021-24107 MED 5.5 microsoft windows_10 Windows Event Tracing Information Disclosure Vulnerability 1.0%
CVE-2021-27364 HIGH 7.1 canonical ubuntu_linux An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages. 1.0%
CVE-2024-30033 HIGH 7.0 microsoft windows_10_21h2 Windows Search Service Elevation of Privilege Vulnerability 1.0%
CVE-2022-43641 HIGH 7.8 foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio 1.0%
CVE-2022-45786 HIGH 8.1 apache age There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for PostgreSQL 11 & AGE for PostgreSQL 12, all versions up-to-and-including 1.1.0, when using those drivers. The fix is to update to the latest G 1.0%
CVE-2020-1122 MED 5.5 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exploi 1.0%
CVE-2013-5539 MED 6.0 cisco identity_services_engine The upload-dialog implementation in Cisco Identity Services Engine (ISE) allows remote authenticated users to upload files with an arbitrary file type, and consequently conduct attacks against unspecified other systems, via a crafted file, aka Bug ID CSCui6751 1.0%