IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-29804 HIGH 7.5 golang go Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack. 2.1%
CVE-2013-5567 MED 5.4 cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software 8.4(.6) and earlier, when using an unsupported configuration with overlapping criteria for filtering and inspection, allows remote attackers to cause a denial of service (traffic loop and device crash) via a pac 2.1%
CVE-2013-2601 HIGH 7.5 citrix xenclient_xt The NDVM in Citrix XenClient XT before 2.1.3 and 3.x before 3.1.4 allows remote attackers to execute arbitrary commands by using the UIVM to create a network connection. 2.1%
CVE-2022-22027 HIGH 7.8 microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability 2.1%
CVE-2019-1572 HIGH 7.5 paloaltonetworks pan-os PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files. 2.1%
CVE-2010-2086 MED 4.0 apache myfaces Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression 2.1%
CVE-2007-0011 MED 5.0 citrix access_gateway The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the 2.1%
CVE-2026-33835 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 2.1%
CVE-2024-43512 MED 6.5 microsoft windows_server_2012 Windows Standards-Based Storage Management Service Denial of Service Vulnerability 2.1%
CVE-2020-3976 MED 5.3 vmware cloud_foundation VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3. 2.1%
CVE-2019-5536 MED 6.5 vmware esxi VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may 2.1%
CVE-2019-1369 MED 5.5 microsoft open_enclave_software_development_kit An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. 2.1%
CVE-2014-9342 MED 4.3 f5 big-ip Cross-site scripting (XSS) vulnerability in the tree view (pl_tree.php) feature in Application Security Manager (ASM) in F5 BIG-IP 11.3.0 allows remote attackers to inject arbitrary web script or HTML by accessing a crafted URL during automatic policy generati 2.1%
CVE-2013-6966 MED 5.8 cisco webex_training_center Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul36031. 2.1%
CVE-2013-6971 MED 5.8 cisco webex_training_center Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul57140. 2.1%
CVE-2013-6967 MED 5.8 cisco webex_sales_center Open redirect vulnerability in the mobile-browser subsystem in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul36020. 2.1%
CVE-2013-6959 MED 5.8 cisco webex_sales_center Open redirect vulnerability in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul25557. 2.1%
CVE-2004-0306 MED 5.0 cisco optical_networking_systems_software Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in the / 2.1%
CVE-2022-35827 HIGH 8.8 microsoft visual_studio Visual Studio Remote Code Execution Vulnerability 2.1%
CVE-2022-35826 HIGH 8.8 microsoft visual_studio Visual Studio Remote Code Execution Vulnerability 2.1%
CVE-2013-1224 HIGH 7.8 cisco unified_customer_voice_portal Directory traversal vulnerability in the Resource Manager in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to overwrite arbitrary files via a crafted (1) HTTP or (2) HTTPS request that triggers incorrect paramete 2.1%
CVE-2011-1283 HIGH 7.2 microsoft windows_2003_server The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 does not ensure that an unspecified array index has a non-nega 2.1%
CVE-2011-1281 HIGH 7.2 microsoft windows_2003_server The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly restric 2.1%
CVE-2021-1487 HIGH 8.8 cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability is due to in 2.1%
CVE-2018-0377 CRIT 9.8 cisco mobility_services_engine A vulnerability in the Open Systems Gateway initiative (OSGi) interface of Cisco Policy Suite before 18.1.0 could allow an unauthenticated, remote attacker to directly connect to the OSGi interface. The vulnerability is due to a lack of authentication. An atta 2.1%