57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-24105 | HIGH 8.4 | microsoft package_manager_configurations <p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package into a package manager's repository which can be retrieved and used during development, build, and release processes. This insertion could le | 2.1% | — |
| CVE-2018-4194 | HIGH 8.8 | apple icloud In iOS before 11.4, iCloud for Windows before 7.5, watchOS before 4.3.1, iTunes before 12.7.5 for Windows, and macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation. | 2.1% | — |
| CVE-2015-1211 | HIGH 7.5 | canonical ubuntu_linux The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android does not properly restrict the URI scheme durin | 2.1% | — |
| CVE-2009-1522 | HIGH 7.1 | ibm tivoli_storage_manager_client The IBM Tivoli Storage Manager (TSM) client 5.5.0.0 through 5.5.1.17 on AIX and Windows, when SSL is used, allows remote attackers to conduct unspecified man-in-the-middle attacks and read arbitrary files via unknown vectors. | 2.1% | — |
| CVE-2011-0426 | MED 4.3 | vmware vcenter Directory traversal vulnerability in vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, and VMware VirtualCenter 2.5 before Update 6a, allows remote attackers to read arbitrary files via unspecified vectors. | 2.1% | — |
| CVE-2023-33150 | CRIT 9.6 | microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability | 2.1% | — |
| CVE-2021-31983 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2021-1236 | MED 5.3 | cisco ios_xe Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection | 2.1% | — |
| CVE-2017-8654 | MED 5.4 | microsoft sharepoint_server Microsoft SharePoint Server 2010 Service Pack 2 allows a cross-site scripting (XSS) vulnerability when it does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability". | 2.1% | — |
| CVE-2016-7460 | CRIT 9.1 | vmware vrealize_automation The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declar | 2.1% | — |
| CVE-2015-0634 | MED 4.3 | cisco webex_meetings_server Cross-site scripting (XSS) vulnerability in the administrative interface in Cisco WebEx Meetings Server 2.5 and 2.5.0.997 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuq86310. | 2.1% | — |
| CVE-2009-1167 | HIGH 10.0 | cisco catalyst_3750g Unspecified vulnerability on the Cisco Wireless LAN Controller (WLC) platform 4.x before 4.2.205.0 and 5.x before 5.2.191.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 4200 Series, and 4400 Series Wireless Services Modules (WiSM), WLC | 2.1% | — |
| CVE-2009-0617 | HIGH 10.0 | cisco application_networking_manager Cisco Application Networking Manager (ANM) before 2.0 uses a default MySQL root password, which makes it easier for remote attackers to execute arbitrary operating-system commands or change system files. | 2.1% | — |
| CVE-2009-0616 | HIGH 10.0 | cisco application_networking_manager Cisco Application Networking Manager (ANM) before 2.0 uses default usernames and passwords, which makes it easier for remote attackers to access the application, or cause a denial of service via configuration changes, related to "default user credentials durin | 2.1% | — |
| CVE-2008-4296 | HIGH 10.0 | cisco linksys_wrt350n The Cisco Linksys WRT350N with firmware 1.0.3.7 has "admin" as its default password for the "admin" account, which makes it easier for remote attackers to obtain access. | 2.1% | — |
| CVE-2005-3803 | HIGH 7.5 | cisco unified_wireless_ip_phone_7920_firmware Cisco IP Phone (VoIP) 7920 1.0(8) contains certain hard-coded ("fixed") public and private SNMP community strings that cannot be changed, which allows remote attackers to obtain sensitive information. | 2.1% | — |
| CVE-2022-23274 | HIGH 8.8 | microsoft dynamics_gp Microsoft Dynamics GP Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2015-7999 | HIGH 8.1 | citrix command_center Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.11 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | 2.1% | — |
| CVE-2013-1333 | HIGH 7.2 | microsoft windows_7 Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overflow Vulnerability." | 2.1% | — |
| CVE-2023-40272 | HIGH 7.5 | apache apache-airflow-providers-apache-spark Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server. It is recommended to upgrade | 2.1% | — |
| CVE-2022-27483 | HIGH 7.2 | fortinet fortianalyzer A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x and FortiAnalyzer version 7.0.0 through 7.0.3, version 6.4.0 through 6.4.7, | 2.1% | — |
| CVE-2021-31471 | MED 5.5 | foxitsoftware 3d This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious f | 2.1% | — |
| CVE-2022-24487 | HIGH 8.8 | microsoft windows_10 Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2019-19448 | HIGH 7.8 | canonical ubuntu_linux In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left | 2.1% | — |
| CVE-2026-33116 | HIGH 7.5 | microsoft .net Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network. | 2.1% | — |