57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-21421 | HIGH 7.5 | microsoft azure_software_development_kit Azure SDK Spoofing Vulnerability | 1.8% | — |
| CVE-2018-7212 | MED 5.3 | sinatrarb sinatra An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows. Path traversal is possible via backslash characters. | 1.8% | — |
| CVE-2017-0339 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. | 1.8% | — |
| CVE-2015-6265 | MED 4.3 | cisco application_control_engine_4700 The CLI in Cisco Application Control Engine (ACE) 4700 A5 3.0 and earlier allows local users to bypass intended access restrictions, and read or write to files, by entering an unspecified CLI command with a crafted file as this command's input, aka Bug ID CSCu | 1.8% | — |
| CVE-2014-2117 | MED 4.3 | cisco emergency_responder Multiple open redirect vulnerabilities in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters, aka Bug ID CSCun37909. | 1.8% | — |
| CVE-2014-2116 | MED 4.3 | cisco emergency_responder Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject web pages and modify dynamic content via unspecified parameters, aka Bug ID CSCun37882. | 1.8% | — |
| CVE-2011-3282 | HIGH 7.8 | cisco ios Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows remote attackers to cause a denial of service (device reload) via an ICMPv6 packet, related to an expi | 1.8% | — |
| CVE-2010-3813 | MED 5.8 | apple safari The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4; webkitgtk before 1.2.6; and possibly other products | 1.8% | — |
| CVE-2000-0955 | HIGH 7.5 | cisco virtual_central_office_4000 Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges. | 1.8% | — |
| CVE-2020-0815 | HIGH 7.5 | microsoft azure_devops_server An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from | 1.8% | — |
| CVE-2018-0087 | MED 5.6 | cisco asyncos A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to the FTP server of the device without a valid password. The attacker does need to have a valid username. The vulnerability i | 1.8% | — |
| CVE-2016-5024 | MED 5.9 | f5 big-ip_access_policy_manager Virtual servers in F5 BIG-IP systems 11.6.1 before 11.6.1 HF1 and 12.1.x before 12.1.2, when configured to parse RADIUS messages via an iRule, allow remote attackers to cause a denial of service (Traffic Management Microkernel restart) via crafted network traf | 1.8% | — |
| CVE-2016-6420 | MED 6.5 | cisco firesight_system_software Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks and gain privileges via a crafted HTTP request, aka Bug ID CSCur25467. | 1.8% | — |
| CVE-2025-47733 | CRIT 9.1 | microsoft power_apps Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network | 1.8% | — |
| CVE-2020-1050 | MED 6.1 | microsoft dynamics_365_server A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. This | 1.8% | — |
| CVE-2015-6418 | MED 4.3 | cisco rv016_multi-wan_vpn_firmware The random-number generator on Cisco Small Business RV routers 4.x and SA500 security appliances 2.2.07 does not have sufficient entropy, which makes it easier for remote attackers to determine a TLS key pair via unspecified computations upon handshake key-exc | 1.8% | — |
| CVE-2023-4973 | LOW 3.5 | creativeitem academy_lms A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument | 1.8% | — |
| CVE-2022-28148 | MED 6.5 | jenkins continuous_integration_with_toad_edge The file browser in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Item/Read permission to obtain the contents o | 1.8% | — |
| CVE-2018-8622 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 1.8% | — |
| CVE-2018-8621 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows Server 2012, Windows 7, Windows Server 2008 R2. This CVE ID is unique f | 1.8% | — |
| CVE-2017-7945 | CRIT 9.8 | paloaltonetworks pan-os The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts depending on whether the username exists, which allows remo | 1.8% | — |
| CVE-2017-0025 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges v | 1.8% | — |
| CVE-1999-0503 | HIGH 7.2 | microsoft windows_2000 A Windows NT local user or administrator account has a guessable password. | 1.8% | — |
| CVE-2022-38046 | HIGH 7.5 | microsoft windows_10 Web Account Manager Information Disclosure Vulnerability | 1.8% | — |
| CVE-2021-28593 | LOW 3.3 | adobe illustrator Adobe Illustrator version 25.2.3 (and earlier) is affected by a Use After Free vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose potential sensitive information in the context of the | 1.8% | — |