57.538 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.538 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-43286 | CRIT 9.8 | f5 njs Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c. | 1.0% | — |
| CVE-2022-22177 | MED 5.3 | juniper junos A release of illegal memory vulnerability in the snmpd daemon of Juniper Networks Junos OS, Junos OS Evolved allows an attacker to halt the snmpd daemon causing a sustained Denial of Service (DoS) to the service until it is manually restarted. This issue impac | 1.0% | — |
| CVE-2021-24006 | MED 6.3 | fortinet fortimanager An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL. | 1.0% | — |
| CVE-2021-34491 | MED 5.5 | microsoft windows_10 Win32k Information Disclosure Vulnerability | 1.0% | — |
| CVE-2021-1417 | CRIT 9.9 | cisco jabber Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, | 1.0% | — |
| CVE-2020-16877 | HIGH 7.1 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Microsoft Windows improperly handles reparse points. An attacker who successfully exploited this vulnerability could overwrite or delete a targeted file that would normally require elevated permissions.</p | 1.0% | — |
| CVE-2017-3869 | MED 5.4 | cisco prime_infrastructure An API Credentials Management vulnerability in the APIs for Cisco Prime Infrastructure could allow an authenticated, remote attacker to access an API that should be restricted to a privileged user. The attacker needs to have valid credentials. More Information | 1.0% | — |
| CVE-2014-3823 | MED 4.3 | juniper junos_pulse_secure_access_service The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 8.0 before 8.0r1, 7.4 before 7.4r5, and 7.1 before 7.1r18 allows remote attackers to conduct clickjacking attacks via unspecified vectors. | 1.0% | — |
| CVE-2014-2193 | MED 4.3 | cisco unified_web_and_e-mail_interaction_manager Cisco Unified Web and E-Mail Interaction Manager places session identifiers in GET requests, which allows remote attackers to inject conversation text by obtaining a valid identifier, aka Bug ID CSCuj43084. | 1.0% | — |
| CVE-2013-3401 | MED 4.3 | cisco telepresence_tc_software The SIP implementation in Cisco TelePresence TC Software allows remote attackers to trigger unintended use of NOTIFY messages via unspecified vectors, aka Bug ID CSCud96080. | 1.0% | — |
| CVE-2013-3376 | MED 4.3 | cisco video_surveillance_operations_manager Open redirect vulnerability in the help page in Cisco Video Surveillance Operations Manager allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCty74490. | 1.0% | — |
| CVE-2011-3649 | LOW 2.6 | mozilla firefox Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by in | 1.0% | — |
| CVE-2026-58281 | HIGH 8.3 | microsoft edge_chromium Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2024-36912 | CRIT 9.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Track decrypted status in vmbus_gpadl In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an err | 1.0% | — |
| CVE-2023-25504 | MED 4.9 | apache superset A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery attacks and query internal resources on behalf of the server where Superset is d | 1.0% | — |
| CVE-2022-35639 | HIGH 7.5 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cause the server to become unresponsive. IBM X-Force ID: 230932. | 1.0% | — |
| CVE-2021-26884 | MED 5.5 | microsoft windows_10 Windows Media Photo Codec Information Disclosure Vulnerability | 1.0% | — |
| CVE-2021-26869 | MED 5.5 | microsoft windows_10 Windows ActiveX Installer Service Information Disclosure Vulnerability | 1.0% | — |
| CVE-2021-24107 | MED 5.5 | microsoft windows_10 Windows Event Tracing Information Disclosure Vulnerability | 1.0% | — |
| CVE-2021-27364 | HIGH 7.1 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages. | 1.0% | — |
| CVE-2024-30033 | HIGH 7.0 | microsoft windows_10_21h2 Windows Search Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-43641 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 1.0% | — |
| CVE-2022-45786 | HIGH 8.1 | apache age There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for PostgreSQL 11 & AGE for PostgreSQL 12, all versions up-to-and-including 1.1.0, when using those drivers. The fix is to update to the latest G | 1.0% | — |
| CVE-2020-1122 | MED 5.5 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exploi | 1.0% | — |
| CVE-2013-5539 | MED 6.0 | cisco identity_services_engine The upload-dialog implementation in Cisco Identity Services Engine (ISE) allows remote authenticated users to upload files with an arbitrary file type, and consequently conduct attacks against unspecified other systems, via a crafted file, aka Bug ID CSCui6751 | 1.0% | — |