57.961 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.961 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-40115 | MED 6.1 | cisco collaboration_meeting_rooms A vulnerability in Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-bas | 0.8% | — |
| CVE-2021-34742 | MED 6.1 | cisco vision_dynamic_signage_director A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerabil | 0.8% | — |
| CVE-2021-34732 | MED 6.1 | cisco prime_collaboration_provisioning A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insuffi | 0.8% | — |
| CVE-2021-1134 | HIGH 7.4 | cisco catalyst_center A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to an incomplete validation | 0.8% | — |
| CVE-2021-1269 | MED 6.3 | cisco data_center_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabili | 0.8% | — |
| CVE-2020-3553 | MED 6.1 | cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabili | 0.8% | — |
| CVE-2020-3515 | MED 6.1 | cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabili | 0.8% | — |
| CVE-2019-5489 | MED 5.5 | linux linux_kernel The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this affects the | 0.8% | — |
| CVE-2018-10876 | MED 5.0 | canonical ubuntu_linux A flaw was found in Linux kernel in the ext4 filesystem code. A use-after-free is possible in ext4_ext_remove_space() function when mounting and operating a crafted ext4 image. | 0.8% | — |
| CVE-2015-7422 | MED 5.5 | ibm i_access Buffer overflow in IBM i Access 7.1 on Windows allows local users to cause a denial of service (application crash) via unspecified vectors. | 0.8% | — |
| CVE-2015-1453 | MED 5.0 | fortinet forticlient The qm class in Fortinet FortiClient 5.2.3.091 for Android uses a hardcoded encryption key of FoRtInEt!AnDrOiD, which makes it easier for attackers to obtain passwords and possibly other sensitive data by leveraging the key to decrypt data in the Shared Prefer | 0.8% | — |
| CVE-2025-21211 | MED 6.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2024-41007 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: avoid too many retransmit packets If a TCP socket is using TCP_USER_TIMEOUT, and the other peer retracted its window to zero, tcp_retransmit_timer() can retransmit a packet every two ji | 0.8% | — |
| CVE-2023-38187 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-32022 | HIGH 7.6 | microsoft windows_server_2012 Windows Server Service Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2023-28866 | MED 5.3 | linux linux_kernel In the Linux kernel through 6.2.8, net/bluetooth/hci_sync.c allows out-of-bounds access because amp_init1[] and amp_init2[] are supposed to have an intentionally invalid element, but do not. | 0.8% | — |
| CVE-2022-35760 | HIGH 7.8 | microsoft windows_10 Microsoft ATA Port Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-29582 | HIGH 7.0 | debian debian_linux In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequ | 0.8% | — |
| CVE-2021-32598 | MED 4.3 | fortinet fortianalyzer An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability In FortiManager and FortiAnalyzer GUI 7.0.0, 6.4.6 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow an authenticated and remote attac | 0.8% | — |
| CVE-2021-1599 | MED 5.4 | cisco unified_customer_voice_portal A vulnerability in the web-based management interface of Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack against a user. This vulnerability is due to insufficient input vali | 0.8% | — |
| CVE-2020-7850 | HIGH 7.8 | douzone nbbdownloader.ocx NBBDownloader.ocx ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. A remote attacker could induce a user to access a crafted web page, causing dama | 0.8% | — |
| CVE-2019-19164 | HIGH 7.8 | raonwiz dext5 dext5.ocx ActiveX Control in Dext5 Upload 5.0.0.112 and earlier versions contains a vulnerability that could allow remote files to be executed by setting the arguments to the activex method. A remote attacker could induce a user to access a crafted web page, c | 0.8% | — |
| CVE-2018-1087 | HIGH 8.0 | canonical ubuntu_linux kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS | 0.8% | — |
| CVE-2017-0435 | HIGH 7.0 | google android An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. | 0.8% | — |
| CVE-2016-1451 | MED 6.1 | cisco meeting_server Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Server (formerly Acano Conferencing Server) 1.7 through 1.9 allows remote attackers to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCva1 | 0.8% | — |