57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1482 | MED 6.3 | microsoft sharepoint_enterprise_server <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially | 2.0% | — |
| CVE-2019-12654 | HIGH 7.5 | cisco ios_xe A vulnerability in the common Session Initiation Protocol (SIP) library of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerabil | 2.0% | — |
| CVE-2019-12653 | HIGH 7.5 | cisco ios_xe A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper parsi | 2.0% | — |
| CVE-2019-12647 | HIGH 7.5 | cisco ios_xe A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability exists because the affected software incorrectly handles memory structures, | 2.0% | — |
| CVE-2009-1202 | MED 4.3 | cisco adaptive_security_appliance WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass certain protection mechanisms involving URL rewriting and HTML rewriting, and conduct cross-site scripting (XSS) attacks, by | 2.0% | — |
| CVE-2025-22828 | MED 4.3 | apache cloudstack CloudStack users can add and read comments (annotations) on resources they are authorised to access. Due to an access validation issue that affects Apache CloudStack versions from 4.16.0, users who have access, prior access or knowledge of resource UUIDs can | 2.0% | — |
| CVE-2023-36892 | HIGH 8.0 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 2.0% | — |
| CVE-2023-36891 | HIGH 8.0 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 2.0% | — |
| CVE-2023-21709 | CRIT 9.8 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2022-21983 | HIGH 7.5 | microsoft windows_10 Win32 Stream Enumeration Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2019-12657 | HIGH 7.5 | cisco ios_xe A vulnerability in Unified Threat Defense (UTD) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper validation of IPv6 packets through the UTD feature. An attacker | 2.0% | — |
| CVE-2019-1962 | HIGH 8.6 | cisco nx-os A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause process crashes, which can result in a denial of service (DoS) condition on an affected system. The vulnerability is due to | 2.0% | — |
| CVE-2015-4328 | MED 4.0 | cisco telepresence_video_communication_server_software Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly checks for a user account's read-only attribute, which allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, as demonstrated by read or wri | 2.0% | — |
| CVE-2015-2829 | HIGH 7.8 | citrix netscaler_application_delivery_controller_firmware Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.5 Build 53.9 through 55.8 and 10.5.e Build 53-9010.e allow remote attackers to cause a denial of service (reboot) via unspecified vectors. | 2.0% | — |
| CVE-2011-0355 | HIGH 7.8 | cisco 1000v_virtual_ethernet_module_\(vem\) Cisco Nexus 1000V Virtual Ethernet Module (VEM) 4.0(4) SV1(1) through SV1(3b), as used in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, does not properly handle dropped packets, which allows guest OS users to cause a denial of service (ESX or ESXi host OS crash | 2.0% | — |
| CVE-2008-4540 | LOW 2.1 | microsoft windows_mobile Windows Mobile 6 on the HTC Hermes device makes WLAN passwords available to an auto-completion mechanism for the password input field, which allows physically proximate attackers to bypass password authentication and obtain WLAN access. | 2.0% | — |
| CVE-2007-1069 | HIGH 7.8 | vmware workstation The memory management in VMware Workstation before 5.5.4 allows attackers to cause a denial of service (Windows virtual machine crash) by triggering certain general protection faults (GPF). | 2.0% | — |
| CVE-2023-25696 | CRIT 9.8 | apache apache-airflow-providers-apache-hive Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3. | 2.0% | — |
| CVE-2022-41056 | HIGH 7.5 | microsoft windows_10 Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability | 2.0% | — |
| CVE-2020-3241 | MED 6.5 | cisco ucs_director A vulnerability in the orchestration tasks of Cisco UCS Director could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input on the web-based | 2.0% | — |
| CVE-2019-1266 | MED 6.1 | microsoft exchange_server A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. | 2.0% | — |
| CVE-2015-4291 | HIGH 7.8 | cisco ios_xe Cisco IOS XE 2.x before 2.4.3 and 2.5.x before 2.5.1 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted series of fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCtd72617. | 2.0% | — |
| CVE-2024-49019 | HIGH 7.8 | microsoft windows_server_2008 Active Directory Certificate Services Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2023-29330 | HIGH 8.8 | microsoft teams Microsoft Teams Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2022-25598 | HIGH 7.5 | apache dolphinscheduler Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher. | 2.0% | — |