56.950 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.950 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-33872 | CRIT 9.8 | fortinet fortitester An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote a | 2.9% | — |
| CVE-2021-28622 | HIGH 7.8 | adobe animate Adobe Animate version 21.0.6 (and earlier) is affected by an Out-of-bounds Write vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue req | 2.9% | — |
| CVE-2021-27079 | MED 5.7 | microsoft windows_10 Windows Media Photo Codec Information Disclosure Vulnerability | 2.9% | — |
| CVE-2020-17150 | HIGH 7.8 | microsoft tslint Visual Studio Code Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2019-17562 | CRIT 9.8 | apache cloudstack A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the mac parameter in baremetal virtual router. If you insert an | 2.9% | — |
| CVE-2010-1571 | HIGH 7.8 | cisco customer_response_solution Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), unspecified 6.0 versions, and 5.0 before 5.0(2)SR3 allows remote attackers to read arbitrary files via a crafted bootstra | 2.9% | — |
| CVE-2018-8207 | MED 4.7 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 2.9% | — |
| CVE-2010-1085 | HIGH 7.1 | linux linux_kernel The azx_position_ok function in hda_intel.c in Linux kernel 2.6.33-rc4 and earlier, when running on the AMD780V chip set, allows context-dependent attackers to cause a denial of service (crash) via unknown manipulations that trigger a divide-by-zero error. | 2.9% | — |
| CVE-2021-27052 | MED 5.3 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Information Disclosure Vulnerability | 2.9% | — |
| CVE-2017-12216 | HIGH 8.8 | cisco socialminer A vulnerability in the web-based user interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to have read and write access to information stored in the affected system. The vulnerability is due to improper handling of XML External Entit | 2.9% | — |
| CVE-2012-4086 | MED 5.1 | cisco unified_computing_system A setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via invalid parameters, aka Bug ID CSCtg20790. | 2.9% | — |
| CVE-2007-1281 | HIGH 7.8 | kaspersky_lab kaspersky_antivirus_engine Kaspersky AntiVirus Engine 6.0.1.411 for Windows and 5.5-10 for Linux allows remote attackers to cause a denial of service (CPU consumption) via a crafted UPX compressed file with a negative offset, which triggers an infinite loop during decompression. | 2.9% | — |
| CVE-2006-3945 | MED 5.0 | opera opera_browser The CSS functionality in Opera 9 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by setting the background property of a DHTML element to a long http or https URL, which triggers memory corruption. | 2.9% | — |
| CVE-2022-32250 | HIGH 7.8 | debian debian_linux net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free. | 2.9% | — |
| CVE-2021-31214 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2016-4921 | HIGH 7.5 | juniper junos By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all available resources can be consumed, leading to the inability to store next hop information for legitimate traffic. In extreme cases, the crafted IPv6 traffic may r | 2.9% | — |
| CVE-2023-36560 | HIGH 8.8 | microsoft .net_framework ASP.NET Security Feature Bypass Vulnerability | 2.9% | — |
| CVE-2019-12407 | MED 6.1 | apache jspwiki On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the remember parameter on some of the JSPs, which could allow the attacker to execute javascript in the vict | 2.9% | — |
| CVE-2019-12404 | MED 6.1 | apache jspwiki On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp, which could allow the attacker to execute javascript in the victim's browser and get some s | 2.9% | — |
| CVE-2019-10087 | MED 6.1 | apache jspwiki On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Page Revision History, which could allow the attacker to execute javascript in the victim's browser and | 2.9% | — |
| CVE-2018-17187 | HIGH 7.4 | apache qpid_proton-j The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a verification mode was explicitly configured, client and server modes previously defaulted as documented to not ve | 2.9% | — |
| CVE-2014-0721 | HIGH 10.0 | cisco unified_sip_phone_3905 The Cisco Unified SIP Phone 3905 with firmware before 9.4(1) allows remote attackers to obtain root access via a session on the test interface on TCP port 7870, aka Bug ID CSCuh75574. | 2.9% | — |
| CVE-2021-31205 | MED 6.5 | microsoft windows_10 Windows SMB Client Security Feature Bypass Vulnerability | 2.9% | — |
| CVE-2017-15717 | MED 6.1 | apache sling_xss_protection_api A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected version | 2.9% | — |
| CVE-2010-4682 | HIGH 7.8 | cisco 5500_series_adaptive_security_appliance Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote attackers to cause a denial of service (memory consumption) by making multiple incorrect LDAP authentication attempts, aka Bug ID CSCtf29867. | 2.9% | — |