57.588 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.588 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-20129 | MED 6.5 | cisco evolved_programmable_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-s | 0.9% | — |
| CVE-2023-20127 | MED 6.5 | cisco prime_infrastructure Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-s | 0.9% | — |
| CVE-2023-21722 | MED 5.0 | microsoft .net_framework .NET Framework Denial of Service Vulnerability | 0.9% | — |
| CVE-2022-38011 | HIGH 7.3 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2020-16887 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>To exploit the vu | 0.9% | — |
| CVE-2020-0647 | MED 5.4 | microsoft office_online_server A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. | 0.9% | — |
| CVE-2017-10623 | HIGH 7.1 | juniper junos_space Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to intercept, inject or disrupt Junos Space cluster operations between two nodes. Affected releases are Juniper Networks | 0.9% | — |
| CVE-2025-54107 | MED 4.3 | microsoft windows_10_1507 Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | 0.9% | — |
| CVE-2024-26201 | MED 6.6 | microsoft intune_company_portal Microsoft Intune Linux Agent Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-20243 | HIGH 8.6 | cisco identity_services_engine A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling o | 0.9% | — |
| CVE-2022-29491 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP LTM, Advanced WAF, ASM, or APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a virtual server is configured with HTTP, TCP on one side (c | 0.9% | — |
| CVE-2022-28705 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, on platforms with an ePVA and the pva.fwdaccel BigDB variable enabled, undisclosed requests to a virtual | 0.9% | — |
| CVE-2022-28701 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, when the stream profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are | 0.9% | — |
| CVE-2022-28691 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when a Real Time Streaming Protocol (RTSP) profile is configured on a virtual server, undisclosed traffic c | 0.9% | — |
| CVE-2022-27189 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when an Internet Content Adaptation Protocol (ICAP) profile is configu | 0.9% | — |
| CVE-2021-23038 | CRIT 9.0 | f5 big-ip_access_policy_manager On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allo | 0.9% | — |
| CVE-2021-20443 | HIGH 8.8 | ibm maximo_for_civil_infrastructure IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is outside of the intended control sphere. IBM X-Force ID: 196619. | 0.9% | — |
| CVE-2020-9345 | MED 6.5 | signotec signopad-api\/web An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the application doesn't limit the number of opened WebSocket sockets. If a victim visits | 0.9% | — |
| CVE-2016-2887 | HIGH 8.1 | ibm ims_enterprise_suite IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors. | 0.9% | — |
| CVE-2016-3710 | HIGH 8.8 | canonical ubuntu_linux The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue. | 0.9% | — |
| CVE-2016-1321 | MED 5.8 | cisco universal_small_cell_firmware Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to bypass a certain certificate-validation feature and obtain sensitive firmware-image and IP address data via a | 0.9% | — |
| CVE-2015-0580 | MED 6.5 | cisco secure_access_control_system Multiple SQL injection vulnerabilities in the ACS View reporting interface pages in Cisco Secure Access Control System (ACS) before 5.5 patch 7 allow remote authenticated administrators to execute arbitrary SQL commands via crafted HTTPS requests, aka Bug ID C | 0.9% | — |
| CVE-2025-21379 | HIGH 7.1 | microsoft windows_11_24h2 DHCP Client Service Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-48747 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: block: Fix wrong offset in bio_truncate() bio_truncate() clears the buffer outside of last block of bdev, however current bio_truncate() is using the wrong offset of page. So it can return t | 0.9% | — |
| CVE-2024-35823 | MED 5.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: vt: fix unicode buffer corruption when deleting characters This is the same issue that was fixed for the VGA text buffer in commit 39cdb68c64d8 ("vt: fix memory overlapping when deleting cha | 0.9% | — |