57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-30067 | MED 5.5 | microsoft windows_10_1507 Winlogon Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-30066 | MED 5.5 | microsoft windows_10_1507 Winlogon Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-37932 | MED 6.5 | fortinet fortivoice An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or | 0.6% | — |
| CVE-2023-36889 | MED 5.5 | microsoft windows_10_1507 Windows Group Policy Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2020-26082 | MED 5.8 | cisco asyncos A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an affected device. The vulnerability is due t | 0.6% | — |
| CVE-2023-33847 | LOW 3.7 | ibm cics_tx IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a | 0.6% | — |
| CVE-2022-27485 | MED 6.5 | fortinet fortisandbox A improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-89] in Fortinet FortiSandbox version 4.2.0, 4.0.0 through 4.0.2, 3.2.0 through 3.2.3, 3.1.x and 3.0.x allows a remote and authenticated attacker with read | 0.6% | — |
| CVE-2021-26625 | HIGH 8.8 | tobesoft nexacro Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers | 0.6% | — |
| CVE-2021-3052 | HIGH 8.0 | paloaltonetworks pan-os A reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface enables an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performs arbitrar | 0.6% | — |
| CVE-2020-3185 | MED 5.4 | cisco telepresence_management_suite A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerabil | 0.6% | — |
| CVE-2020-3113 | MED 5.4 | cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerabili | 0.6% | — |
| CVE-2007-3184 | HIGH 7.2 | apple mac_os_x Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server (ACS) produces a use | 0.6% | — |
| CVE-2024-56627 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read An offset from client could be a negative value, It could lead to an out-of-bounds read from the stream_buf. Note that this issue is co | 0.6% | — |
| CVE-2021-1466 | MED 5.4 | cisco catalyst_sd-wan_manager A vulnerability in the vDaemon service of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to cause a buffer overflow on an affected system, resulting in a denial of service (DoS) condition. The vulnerability is due to inco | 0.6% | — |
| CVE-2024-43546 | MED 5.6 | microsoft windows_10_21h2 Windows Cryptographic Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-26620 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: always filter entire AP matrix The vfio_ap_mdev_filter_matrix function is called whenever a new adapter or domain is assigned to the mdev. The purpose of the function is to upd | 0.6% | — |
| CVE-2021-46983 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: Fix NULL deref when SEND is completed with error When running some traffic and taking down the link on peer, a retry counter exceeded error is received. This leads to nvmet_rdma_ | 0.6% | — |
| CVE-2023-38141 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-44671 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-40133 | MED 6.3 | linux linux_kernel A use-after-free(UAF) vulnerability was found in function 'vmw_execbuf_tie_context' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account o | 0.6% | — |
| CVE-2022-28707 | HIGH 8.0 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility (also referred to as t | 0.6% | — |
| CVE-2020-25669 | HIGH 7.8 | debian debian_linux A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before sunkbd being freed. Though the dangling pointer is set to NULL in sunkbd_disconnect, there is still an alias in sunkbd_reinit causin | 0.6% | — |
| CVE-2020-1645 | HIGH 8.3 | juniper junos When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process, responsible for managing "URL Filt | 0.6% | — |
| CVE-2020-1980 | HIGH 7.8 | paloaltonetworks pan-os A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. This issue affects only PAN-OS 8.1 versions earlier than PAN-OS 8.1.13. This issue does not affect PAN-OS 7.1, P | 0.6% | — |
| CVE-2019-14835 | HIGH 7.8 | canonical ubuntu_linux A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with i | 0.6% | — |