IT
57.961 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.961 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2016-1431 MED 6.1 cisco secure_firewall_management_center Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCur25516. 0.8%
CVE-2016-1375 MED 6.1 cisco ip_interoperability_and_collaboration_system Cross-site scripting (XSS) vulnerability in Cisco IP Interoperability and Collaboration System 4.10(1) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy12339. 0.8%
CVE-2016-1354 MED 6.1 cisco unified_communications_domain_manager Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 8.x before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data, aka Bug ID CSCud41176. 0.8%
CVE-2016-1300 MED 6.1 cisco unity_connection Cross-site scripting (XSS) vulnerability in Cisco Unity Connection (UC) 10.5(2.3009) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux82582. 0.8%
CVE-2015-4239 MED 6.1 cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software 9.3(2.243) and 100.13(0.21) allows remote attackers to cause a denial of service (device reload) by sending crafted OSPFv2 packets on the local network, aka Bug ID CSCus84220. 0.8%
CVE-2012-6606 MED 5.8 paloaltonetworks globalprotect Palo Alto Networks GlobalProtect before 1.1.7, and NetConnect, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof portal servers and obtain sensitive information via a crafted certificate. 0.8%
CVE-2011-1424 LOW 3.5 emc sourceone_email_management The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the trace element, which allows remote authenticated users to obta 0.8%
CVE-2007-1730 MED 6.6 linux linux_kernel Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local users to read kernel memory or cause a denial of service (oops) via a negative optlen value. 0.8%
CVE-2026-81377 MED 6.5 microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. 0.8%
CVE-2024-5494 HIGH 8.8 fedoraproject fedora Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.8%
CVE-2024-27393 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xen-netfront: Add missing skb_mark_for_recycle Notice that skb_mark_for_recycle() is introduced later than fixes tag in commit 6a5bcd84e886 ("page_pool: Allow drivers to hint on SKB recyclin 0.8%
CVE-2022-40677 HIGH 7.2 fortinet fortinac A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allow 0.8%
CVE-2022-46872 HIGH 8.6 mozilla firefox An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability aff 0.8%
CVE-2022-45461 HIGH 7.5 veritas netbackup The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root. 0.8%
CVE-2022-21865 HIGH 7.0 microsoft windows_10 Connected Devices Platform Service Elevation of Privilege Vulnerability 0.8%
CVE-2022-21864 HIGH 7.0 microsoft windows_10 Windows UI Immersive Server API Elevation of Privilege Vulnerability 0.8%
CVE-2022-21860 HIGH 7.0 microsoft windows_10 Windows AppContracts API Server Elevation of Privilege Vulnerability 0.8%
CVE-2021-1709 HIGH 7.0 microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability 0.8%
CVE-2020-3301 MED 4.4 cisco secure_firewall_management_center Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account. For more information about these vulne 0.8%
CVE-2019-1007 HIGH 7.8 microsoft windows_10 An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that coul 0.8%
CVE-2017-14946 HIGH 7.8 artifex gsview Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at mupdfnet64!mIncrementalSaveFile+0x0 0.8%
CVE-2017-14945 HIGH 7.8 artifex gsview Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Possible Stack Corruption starting at KERNELBASE!RaiseException+0x0000000000000068." 0.8%
CVE-2015-6311 MED 6.1 cisco wireless_lan_controller Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0), 7.3(101.0), and 7.4(1.19) allow remote attackers to cause a denial of service (device outage) by sending malformed 802.11i management data to a managed access point, aka Bug ID CSCub65236. 0.8%
CVE-2015-6294 MED 6.1 cisco ios Cisco IOS 15.2(3)E and earlier and IOS XE 3.6(2)E and earlier allow remote attackers to cause a denial of service (functionality loss) via crafted Cisco Discovery Protocol (CDP) packets, aka Bug ID CSCuu25770. 0.8%
CVE-2015-4243 MED 6.1 cisco ios_xe The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote attackers to cause a denial of service (device reload) by sending malformed PPPoE Active Discovery Request (PADR) packets on the local network, aka Bug ID CSCty9420 0.8%