57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-42474 | MED 6.5 | fortinet fortios A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2.0 through 7.2.1 and | 0.6% | — |
| CVE-2022-43955 | HIGH 8.8 | fortinet fortiweb An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.3, 6.3.0 through 6.3.21, 6.4 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow an unauthenticated and remote a | 0.6% | — |
| CVE-2023-21802 | HIGH 7.8 | microsoft windows_10 Windows Media Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2022-45431 | HIGH 7.5 | dahuasecurity dhi-dss4004-s2_firmware Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated restart o | 0.6% | — |
| CVE-2022-20689 | MED 5.3 | cisco ata_190_firmware Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause Cisco Discovery Protocol memory corruption on an affected device. Thes | 0.6% | — |
| CVE-2022-38405 | HIGH 7.8 | adobe incopy Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i | 0.6% | — |
| CVE-2022-38404 | HIGH 7.8 | adobe incopy Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i | 0.6% | — |
| CVE-2022-38403 | HIGH 7.8 | adobe incopy Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i | 0.6% | — |
| CVE-2022-23291 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-22001 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2020-9442 | HIGH 7.8 | openvpn connect OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there. | 0.6% | — |
| CVE-2018-0220 | MED 5.4 | cisco videoscape_anyres_live A vulnerability in the web-based management interface of Cisco Videoscape AnyRes Live could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The v | 0.6% | — |
| CVE-2017-12358 | MED 5.4 | cisco jabber A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vuln | 0.6% | — |
| CVE-2017-6717 | MED 5.4 | cisco secure_firewall_management_center A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc38801. Known Affected Releases: 6 | 0.6% | — |
| CVE-2017-6716 | MED 5.4 | cisco secure_firewall_management_center A vulnerability in the web framework code of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. Affected Products: Cis | 0.6% | — |
| CVE-2017-6715 | MED 5.4 | cisco secure_firewall_management_center A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. Affected Products: Cisco Firepower Management Center Rel | 0.6% | — |
| CVE-2013-6208 | HIGH 7.2 | hp smart_update_manager Unspecified vulnerability in HP Smart Update Manager 5.3.5 before build 70 on Linux allows local users to gain privileges via unknown vectors. | 0.6% | — |
| CVE-2019-17659 | LOW 3.7 | fortinet fortisiem A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted user "tunneluser" by leveraging knowledge of the private key from another instal | 0.6% | — |
| CVE-2025-21315 | HIGH 7.8 | microsoft windows_11_24h2 Microsoft Brokering File System Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-20853 | HIGH 7.4 | cisco telepresence_video_communication_server A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insuffi | 0.6% | — |
| CVE-2022-33682 | MED 5.9 | apache pulsar TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, the Pulsar WebSocket Proxy's Java Client, and the Pulsar Proxy's Admin Client leaving intra-cluster connections and geo-replication connectio | 0.6% | — |
| CVE-2022-35797 | MED 6.1 | microsoft windows_10 Windows Hello Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2022-24459 | HIGH 7.8 | microsoft windows_10 Windows Fax and Scan Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-20560 | MED 5.4 | ibm sterling_connect_direct_user_interface IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack | 0.6% | — |
| CVE-2020-5915 | MED 6.1 | f5 big-ip_access_policy_manager In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, an undisclosed TMUI page contains a vulnerability which allows a stored XSS when BIG-IP systems are setup in a device trust. | 0.6% | — |