57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1843 | HIGH 8.6 | cisco rv110w_firmware A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to cause a reload of an | 2.2% | — |
| CVE-2014-0673 | MED 4.3 | cisco video_surveillance_indoor_fixed_dome_ip_hd_camera Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Cisco Video Surveillance 5000 HD IP Dome cameras allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCud10943 and CSCud10950. | 2.2% | — |
| CVE-2014-0670 | MED 4.3 | cisco mediasense Cross-site scripting (XSS) vulnerability in the Search and Play interface in Cisco MediaSense allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCum16686. | 2.2% | — |
| CVE-2014-0652 | MED 4.3 | cisco context_directory_agent Cross-site scripting (XSS) vulnerability in the Mappings page in Cisco Context Directory Agent (CDA) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuj45358. | 2.2% | — |
| CVE-2020-1654 | CRIT 9.8 | juniper junos On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, processing a malformed HTTP message can lead to a Denial of Service (DoS) or Remote Code Execution (RCE) Continued processing of this malformed HTTP messa | 2.2% | — |
| CVE-2016-7300 | HIGH 7.8 | microsoft auto_updater_for_mac Untrusted search path vulnerability in Microsoft Auto Updater for Mac allows local users to gain privileges via a Trojan horse executable file, aka "Microsoft (MAU) Office Elevation of Privilege Vulnerability." | 2.2% | — |
| CVE-2021-36004 | HIGH 8.8 | adobe indesign Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability in the CoolType library. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitati | 2.2% | — |
| CVE-2012-0335 | MED 5.0 | cisco 5500_series_adaptive_security_appliance Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not properly perform proxy authentication during attempts to cut through a firewall, which allows remote attackers to obtain sensitive information via a connection at | 2.2% | — |
| CVE-2024-46662 | HIGH 8.8 | fortinet fortimanager A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted pac | 2.2% | — |
| CVE-2025-21311 | CRIT 9.8 | microsoft windows_11_24h2 Windows NTLM V1 Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2024-38149 | HIGH 7.5 | microsoft windows_10_1507 BranchCache Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-38199 | CRIT 9.8 | microsoft windows_10_1507 Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-40144 | CRIT 9.8 | trendmicro apex_one A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by falsifying request parameters on affected installations. | 2.2% | — |
| CVE-2022-24516 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2020-1456 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- | 2.2% | — |
| CVE-2020-4494 | HIGH 7.5 | ibm spectrum_protect_client IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow an attacker to by | 2.2% | — |
| CVE-2018-8568 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.2% | — |
| CVE-2016-1000104 | HIGH 8.8 | apache mod_fcgid A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07. | 2.2% | — |
| CVE-2014-3816 | HIGH 9.0 | juniper junos Juniper Junos 11.4 before 11.4R12, 12.1 before 12.1R11, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47-D10, 12.2 before 12.2R8-S2, 12.3 before 12.3R7, 13.1 before 13.1R4-S2, 13.2 before 13.2R5, 13.3 b | 2.2% | — |
| CVE-2004-0115 | MED 4.6 | microsoft virtual_pc VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file. | 2.2% | — |
| CVE-2022-33654 | MED 4.9 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2018-15505 | HIGH 7.5 | embedthis appweb An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trail | 2.2% | — |
| CVE-2018-0113 | HIGH 8.8 | cisco unified_computing_system_central_software A vulnerability in an operations script of Cisco UCS Central could allow an authenticated, remote attacker to execute arbitrary shell commands with the privileges of the daemon user. The vulnerability is due to insufficient input validation. An attacker could | 2.2% | — |
| CVE-2020-3426 | HIGH 7.5 | cisco ios A vulnerability in the implementation of the Low Power, Wide Area (LPWA) subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthe | 2.2% | — |
| CVE-2016-3372 | MED 6.6 | microsoft windows_server_2008 The kernel API in Microsoft Windows Vista SP2 and Windows Server 2008 SP2 does not properly enforce permissions, which allows local users to spoof processes, spoof inter-process communication, or cause a denial of service via a crafted application, aka "Window | 2.2% | — |