57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-35221 | MED 6.3 | solarwinds orion_platform Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings page. | 2.0% | — |
| CVE-2013-7408 | HIGH 7.5 | f5 big-ip_analytics F5 BIG-IP Analytics 11.x before 11.4.0 uses a predictable session cookie, which makes it easier for remote attackers to have unspecified impact by guessing the value. | 2.0% | — |
| CVE-2021-29688 | HIGH 7.5 | ibm security_identity_manager IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 200102. | 2.0% | — |
| CVE-2021-28447 | MED 4.4 | microsoft windows_10 Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability | 2.0% | — |
| CVE-2020-3386 | HIGH 8.8 | cisco data_center_network_manager A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privileged account to bypass authorization on the API of an affected device. The vulnerability is due to insufficient | 2.0% | — |
| CVE-2014-3825 | MED 6.8 | juniper junos The Juniper SRX Series devices with Junos 11.4 before 11.4R12-S4, 12.1X44 before 12.1X44-D40, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D25, and 12.1X47 before 12.1X47-D10, when an Application Layer Gateway (ALG) is enabled, allows remote attackers to | 2.0% | — |
| CVE-2009-3832 | MED 5.8 | opera opera_browser Opera before 10.01 on Windows does not prevent use of Web fonts in rendering the product's own user interface, which allows remote attackers to spoof the address field via a crafted web site. | 2.0% | — |
| CVE-2020-15138 | HIGH 7.1 | prismjs previewers Prism is vulnerable to Cross-Site Scripting. The easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to execute arbitrary code in Safari and Internet Explorer. This impacts all Safari and Internet Explorer users of Prism >=v1 | 2.0% | — |
| CVE-2018-0382 | MED 5.3 | cisco wireless_lan_controller_software A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerab | 2.0% | — |
| CVE-2019-6226 | HIGH 8.8 | apple icloud Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lea | 2.0% | — |
| CVE-2019-6217 | HIGH 8.8 | apple icloud Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lea | 2.0% | — |
| CVE-2019-6216 | HIGH 8.8 | apple icloud Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lea | 2.0% | — |
| CVE-2016-7914 | MED 5.5 | linux linux_kernel The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid | 2.0% | — |
| CVE-2024-49089 | HIGH 7.2 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2018-8164 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 20 | 2.0% | — |
| CVE-2016-9149 | MED 6.5 | paloaltonetworks pan-os The Addresses Object parser in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 mishandles single quote characters, which allows remote authenticated users to co | 2.0% | — |
| CVE-2015-6113 | LOW 2.1 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass intended filesystem permis | 2.0% | — |
| CVE-2013-6706 | MED 5.4 | cisco ios_xe The Cisco Express Forwarding processing module in Cisco IOS XE allows remote attackers to cause a denial of service (device reload) via crafted MPLS packets that are not properly handled during IP header validation, aka Bug ID CSCuj23992. | 2.0% | — |
| CVE-2013-1156 | MED 5.0 | cisco prime_central_for_hosted_collaboration_solution Directory traversal vulnerability in Cisco Prime Central for Hosted Collaboration Solution allows remote attackers to read arbitrary files via a crafted URL, aka Bug ID CSCud51034. | 2.0% | — |
| CVE-2008-1364 | HIGH 7.8 | vmware ace Unspecified vulnerability in the DHCP service in VMware Workstation 5.5.x before 5.5.6, VMware Player 1.0.x before 1.0.6, VMware ACE 1.0.x before 1.0.5, VMware Server 1.0.x before 1.0.5, and VMware Fusion 1.1.x before 1.1.1 allows attackers to cause a denial o | 2.0% | — |
| CVE-2024-20680 | MED 6.5 | microsoft windows_10_1507 Windows Message Queuing Client (MSMQC) Information Disclosure | 2.0% | — |
| CVE-2024-20660 | MED 6.5 | microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability | 2.0% | — |
| CVE-2019-1708 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker | 2.0% | — |
| CVE-2017-4919 | CRIT 9.0 | vmware vcenter_server VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate. | 2.0% | — |
| CVE-2009-0016 | MED 5.0 | apple itunes Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite loop) via a Digital Audio Access Protocol (DAAP) message with a crafted Content-Length header. | 2.0% | — |