57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-29804 | HIGH 7.5 | golang go Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack. | 2.1% | — |
| CVE-2013-5567 | MED 5.4 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software 8.4(.6) and earlier, when using an unsupported configuration with overlapping criteria for filtering and inspection, allows remote attackers to cause a denial of service (traffic loop and device crash) via a pac | 2.1% | — |
| CVE-2013-2601 | HIGH 7.5 | citrix xenclient_xt The NDVM in Citrix XenClient XT before 2.1.3 and 3.x before 3.1.4 allows remote attackers to execute arbitrary commands by using the UIVM to create a network connection. | 2.1% | — |
| CVE-2022-22027 | HIGH 7.8 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2019-1572 | HIGH 7.5 | paloaltonetworks pan-os PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files. | 2.1% | — |
| CVE-2010-2086 | MED 4.0 | apache myfaces Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression | 2.1% | — |
| CVE-2007-0011 | MED 5.0 | citrix access_gateway The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the | 2.1% | — |
| CVE-2026-33835 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 2.1% | — |
| CVE-2024-43512 | MED 6.5 | microsoft windows_server_2012 Windows Standards-Based Storage Management Service Denial of Service Vulnerability | 2.1% | — |
| CVE-2020-3976 | MED 5.3 | vmware cloud_foundation VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3. | 2.1% | — |
| CVE-2019-5536 | MED 6.5 | vmware esxi VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may | 2.1% | — |
| CVE-2019-1369 | MED 5.5 | microsoft open_enclave_software_development_kit An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. | 2.1% | — |
| CVE-2014-9342 | MED 4.3 | f5 big-ip Cross-site scripting (XSS) vulnerability in the tree view (pl_tree.php) feature in Application Security Manager (ASM) in F5 BIG-IP 11.3.0 allows remote attackers to inject arbitrary web script or HTML by accessing a crafted URL during automatic policy generati | 2.1% | — |
| CVE-2013-6966 | MED 5.8 | cisco webex_training_center Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul36031. | 2.1% | — |
| CVE-2013-6971 | MED 5.8 | cisco webex_training_center Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul57140. | 2.1% | — |
| CVE-2013-6967 | MED 5.8 | cisco webex_sales_center Open redirect vulnerability in the mobile-browser subsystem in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul36020. | 2.1% | — |
| CVE-2013-6959 | MED 5.8 | cisco webex_sales_center Open redirect vulnerability in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul25557. | 2.1% | — |
| CVE-2004-0306 | MED 5.0 | cisco optical_networking_systems_software Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in the / | 2.1% | — |
| CVE-2022-35827 | HIGH 8.8 | microsoft visual_studio Visual Studio Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2022-35826 | HIGH 8.8 | microsoft visual_studio Visual Studio Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2013-1224 | HIGH 7.8 | cisco unified_customer_voice_portal Directory traversal vulnerability in the Resource Manager in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to overwrite arbitrary files via a crafted (1) HTTP or (2) HTTPS request that triggers incorrect paramete | 2.1% | — |
| CVE-2011-1283 | HIGH 7.2 | microsoft windows_2003_server The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 does not ensure that an unspecified array index has a non-nega | 2.1% | — |
| CVE-2011-1281 | HIGH 7.2 | microsoft windows_2003_server The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly restric | 2.1% | — |
| CVE-2021-1487 | HIGH 8.8 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability is due to in | 2.1% | — |
| CVE-2018-0377 | CRIT 9.8 | cisco mobility_services_engine A vulnerability in the Open Systems Gateway initiative (OSGi) interface of Cisco Policy Suite before 18.1.0 could allow an unauthenticated, remote attacker to directly connect to the OSGi interface. The vulnerability is due to a lack of authentication. An atta | 2.1% | — |