57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-0742 | MED 5.4 | microsoft team_foundation_server A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0743. | 1.8% | — |
| CVE-2015-3005 | MED 4.3 | juniper junos Cross-site scripting (XSS) vulnerability in the Dynamic VPN in Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, and 12.3X48 before 12.3X48-D10 on SRX series devices allows remote attackers to inject arbitrary we | 1.8% | — |
| CVE-2015-0655 | MED 4.3 | cisco unified_web_and_e-mail_interaction_manager Cross-site scripting (XSS) vulnerability in Unified Web Interaction Manager in Cisco Unified Web and E-Mail Interaction Manager allows remote attackers to inject arbitrary web script or HTML via vectors related to a POST request, aka Bug ID CSCus74184. | 1.8% | — |
| CVE-2014-8018 | MED 4.3 | cisco unified_communications_domain_manager Multiple cross-site scripting (XSS) vulnerabilities in Business Voice Services Manager (BVSM) pages in the Application Software in Cisco Unified Communications Domain Manager 8 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, ak | 1.8% | — |
| CVE-2013-6957 | MED 4.3 | juniper idp250 Cross-site scripting (XSS) vulnerability in the web administrative component in Juniper IDP allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to the ACM web server. | 1.8% | — |
| CVE-2013-5501 | MED 4.3 | cisco mediasense Cross-site scripting (XSS) vulnerability in the oraservice page in Cisco MediaSense allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuj23328. | 1.8% | — |
| CVE-2013-5500 | MED 4.3 | cisco mediasense Multiple cross-site scripting (XSS) vulnerabilities in the oraadmin service page in Cisco MediaSense allow remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug IDs CSCuj23320, CSCuj23324, CSCuj23333, and CSCuj23338. | 1.8% | — |
| CVE-2010-2740 | HIGH 7.2 | microsoft windows_2003_server The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font parsing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Parsing Vul | 1.8% | — |
| CVE-2024-39864 | CRIT 9.8 | apache cloudstack The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integration.api.port global setting) for internal portal integrations and for testing purposes. By default, the integrati | 1.8% | — |
| CVE-2023-39410 | HIGH 7.5 | apache avro When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11 | 1.8% | — |
| CVE-2022-37401 | HIGH 8.8 | apache openoffice Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where master key was poorly encoded res | 1.8% | — |
| CVE-2020-24560 | HIGH 7.5 | trendmicro antivirus\+_2019 An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a maliciou | 1.8% | — |
| CVE-2020-1205 | MED 4.6 | microsoft sharepoint_enterprise_server <p>A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to | 1.8% | — |
| CVE-2019-12673 | HIGH 7.5 | cisco adaptive_security_appliance A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vul | 1.8% | — |
| CVE-2019-1892 | HIGH 7.5 | cisco esw2-350g52dc_firmware A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a memory corruption on an affected device. The vulnerability is | 1.8% | — |
| CVE-2019-1891 | HIGH 7.5 | cisco esw2-350g52dc_firmware A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper vali | 1.8% | — |
| CVE-2019-1887 | HIGH 8.6 | cisco unified_communications_manager A vulnerability in the Session Initiation Protocol (SIP) protocol implementation of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient vali | 1.8% | — |
| CVE-2019-1817 | HIGH 7.5 | cisco web_security_appliance A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper v | 1.8% | — |
| CVE-2013-3907 | HIGH 7.2 | microsoft windows_7 portcls.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Port-Class Driver Dou | 1.8% | — |
| CVE-2013-1195 | MED 5.0 | cisco adaptive_security_appliance_software The time-based ACL implementation on Cisco Adaptive Security Appliances (ASA) devices, and in Cisco Firewall Services Module (FWSM), does not properly handle periodic statements for the time-range command, which allows remote attackers to bypass intended acces | 1.8% | — |
| CVE-2002-2324 | HIGH 7.2 | microsoft windows_xp The "System Restore" directory and subdirectories, and possibly other subdirectories in the "System Volume Information" directory on Windows XP Professional, have insecure access control list (ACL) permissions, which allows local users to access restricted fil | 1.8% | — |
| CVE-2026-27909 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | 1.8% | — |
| CVE-2019-3874 | MED 6.5 | canonical ubuntu_linux The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable. | 1.8% | — |
| CVE-2002-0505 | MED 5.0 | cisco call_manager Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) via a series of authentication failures, e.g. via incorrect pas | 1.8% | — |
| CVE-2011-3296 | HIGH 7.8 | cisco catalyst_6500 Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when IPv6 is used, allows remote attackers to cause a denial of service (memory corruption and module crash or hang) via vectors that t | 1.8% | — |