57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-1362 | HIGH 7.5 | cisco aireos Cisco AireOS 4.1 through 7.4.120.0, 7.5.x, and 7.6.100.0 on Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of service (device reload) via a crafted HTTP request, aka Bug ID CSCun86747. | 2.1% | — |
| CVE-2016-1296 | HIGH 7.5 | cisco web_security_appliance The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows remote attackers to bypass intended proxy restrictions via a malformed HTTP method, aka Bug ID CSCux00848. | 2.1% | — |
| CVE-2013-6963 | MED 4.3 | cisco webex_training_center Cross-site scripting (XSS) vulnerability in the registration component in Cisco WebEx Training Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36207. | 2.1% | — |
| CVE-2013-6690 | MED 4.3 | cisco prime_collaboration Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Assurance component in Cisco Prime Collaboration allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs CSCui92643, CSCui94038, and CSCu | 2.1% | — |
| CVE-2022-20753 | MED 4.7 | cisco rv340_firmware A vulnerability in web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-suppli | 2.1% | — |
| CVE-2019-19767 | MED 5.5 | linux linux_kernel The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry, related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163. | 2.1% | — |
| CVE-2018-4345 | MED 6.1 | apple icloud A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7. | 2.1% | — |
| CVE-2018-4311 | HIGH 8.1 | apple icloud The issue was addressed by removing origin information. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7. | 2.1% | — |
| CVE-2017-14184 | HIGH 8.8 | fortinet forticlient An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's | 2.1% | — |
| CVE-2014-2313 | MED 4.3 | atlassian jira Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to create arbitrary files via unspecified vectors. | 2.1% | — |
| CVE-2010-1383 | HIGH 9.3 | apple cfnetwork CFNetwork in Apple Safari before 5.0.6 on Windows allows remote web servers to execute arbitrary code by replaying the NTLM credentials of a client user, related to a "credential reflection" issue. | 2.1% | — |
| CVE-2010-0819 | HIGH 7.2 | microsoft windows_2000 Unspecified vulnerability in the Windows OpenType Compact Font Format (CFF) driver in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users to execute arbitrary code via unknown | 2.1% | — |
| CVE-1999-1216 | HIGH 7.5 | cisco router Cisco routers 9.17 and earlier allow remote attackers to bypass security restrictions via certain IP source routed packets that should normally be denied using the "no ip source-route" command. | 2.1% | — |
| CVE-2023-35390 | HIGH 7.8 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2021-45458 | HIGH 7.5 | apache kylin Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by this encryption class, the cipher is initialized with a hardcoded key and IV. If users use class PasswordPlacehold | 2.1% | — |
| CVE-2018-0260 | MED 5.3 | cisco mate_live A vulnerability in the web interface of Cisco MATE Live could allow an unauthenticated, remote attacker to view and download the contents of certain web application virtual directories. The vulnerability is due to lack of proper input validation and authorizat | 2.1% | — |
| CVE-2018-0747 | MED 4.7 | microsoft windows_10 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulne | 2.1% | — |
| CVE-2025-54539 | CRIT 9.8 | apache activemq_nms_amqp A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2.3.0, when establishing connections to untrusted AMQP servers. Malicious servers | 2.1% | — |
| CVE-2024-21356 | MED 6.5 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | 2.1% | — |
| CVE-2021-31173 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Server Information Disclosure Vulnerability | 2.1% | — |
| CVE-2021-27365 | HIGH 7.8 | debian debian_linux An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, a | 2.1% | — |
| CVE-2019-19362 | MED 6.5 | teamviewer teamviewer An issue was discovered in the Chat functionality of the TeamViewer desktop application 14.3.4730 on Windows. (The vendor states that it was later fixed.) Upon login, every communication is saved within Windows main memory. When a user logs out or deletes conv | 2.1% | — |
| CVE-2018-1319 | MED 6.1 | apache allura In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's browsing session. | 2.1% | — |
| CVE-2014-0677 | MED 5.0 | cisco nx-os The Label Distribution Protocol (LDP) functionality in Cisco NX-OS allows remote attackers to cause a denial of service (temporary LDP session outage) via LDP discovery traffic containing malformed Hello messages, aka Bug ID CSCul88851. | 2.1% | — |
| CVE-2013-3198 | HIGH 7.2 | microsoft windows_7 The NT Virtual DOS Machine (NTVDM) subsystem in the kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly validate kernel-memory addresses, wh | 2.1% | — |