57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-3340 | MED 4.0 | cisco webex_meetmenow Directory traversal vulnerability in an unspecified PHP script in the server in Cisco WebEx MeetMeNow allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCuo16166. | 2.3% | — |
| CVE-1999-0593 | MED 4.9 | microsoft windows_nt The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. | 2.3% | — |
| CVE-2021-45052 | LOW 3.3 | adobe bridge Adobe Bridge version 11.1.2 (and earlier) and version 12.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex | 2.3% | — |
| CVE-2021-31914 | CRIT 9.8 | jetbrains teamcity In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible. | 2.3% | — |
| CVE-2021-1393 | CRIT 9.8 | cisco application_policy_infrastructure_controller Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-specific information, create diagnostic files, and make limited configuration ch | 2.3% | — |
| CVE-2013-0892 | HIGH 7.5 | google chrome Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors. | 2.3% | — |
| CVE-2022-35825 | HIGH 8.8 | microsoft visual_studio Visual Studio Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-24072 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-21053 | HIGH 7.8 | adobe illustrator Adobe Illustrator version 25.1 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. | 2.2% | — |
| CVE-2024-49070 | HIGH 7.4 | microsoft sharepoint_server Microsoft SharePoint Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2020-2010 | HIGH 7.2 | paloaltonetworks pan-os An OS command injection vulnerability in PAN-OS management interface allows an authenticated administrator to execute arbitrary OS commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; P | 2.2% | — |
| CVE-2020-2007 | HIGH 7.2 | paloaltonetworks pan-os An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to potentially execute arbitrary commands with root privileges. This issue affects: All PAN-OS 7.1 versions; PAN-OS 8.1 versions earlier than 8.1.14 | 2.2% | — |
| CVE-2020-5868 | CRIT 9.8 | f5 big-iq_centralized_management In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell commands on affected systems using HTTP requests to the BIG-IQ user interface. | 2.2% | — |
| CVE-2019-1631 | MED 5.3 | cisco integrated_management_controller A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitive system usage information. The vulnerability is due to a lack of proper data pr | 2.2% | — |
| CVE-2018-4213 | HIGH 8.8 | apple icloud In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks. | 2.2% | — |
| CVE-2018-0403 | CRIT 9.8 | cisco unified_contact_center_express Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. Cisco Bug IDs: CSCvg71040. | 2.2% | — |
| CVE-2023-38435 | MED 6.1 | apache felix_health_check_webconsole_plugin An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. | 2.2% | — |
| CVE-2021-33782 | MED 5.5 | microsoft windows_10 Windows Authenticode Spoofing Vulnerability | 2.2% | — |
| CVE-2017-12354 | MED 5.3 | cisco secure_access_control_system A vulnerability in the web-based interface of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected software does not sufficie | 2.2% | — |
| CVE-2022-21979 | MED 4.8 | microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability | 2.2% | — |
| CVE-2015-4235 | HIGH 9.0 | cisco application_policy_infrastructure_controller_\(apic\) Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with software before 11.0(4o) and 11.1 before 11.1(1j) do not properly restrict access to the APIC filesystem, whic | 2.2% | — |
| CVE-2020-26085 | CRIT 9.9 | cisco jabber Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive informati | 2.2% | — |
| CVE-2020-9744 | MED 6.1 | adobe media_encoder Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locati | 2.2% | — |
| CVE-2020-9739 | MED 6.1 | adobe media_encoder Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locati | 2.2% | — |
| CVE-2020-0887 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0788, CVE-2020-0877. | 2.2% | — |