57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1036 | MED 5.4 | microsoft project_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra | 1.7% | — |
| CVE-2019-1033 | MED 5.4 | microsoft project_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra | 1.7% | — |
| CVE-2019-1032 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra | 1.7% | — |
| CVE-2019-1031 | MED 5.4 | microsoft project_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra | 1.7% | — |
| CVE-2019-1228 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerabili | 1.7% | — |
| CVE-2019-1227 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerabili | 1.7% | — |
| CVE-2019-1154 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system. There are mu | 1.7% | — |
| CVE-2019-1143 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system. There are mu | 1.7% | — |
| CVE-2019-0562 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 1.7% | — |
| CVE-2018-1354 | MED 6.5 | fortinet fortianalyzer An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content. | 1.7% | — |
| CVE-2017-6656 | MED 5.9 | cisco ip_phone_8800_series A vulnerability in Session Initiation Protocol (SIP) call handling of Cisco IP Phone 8800 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the SIP process unexpectedly restarting. All active pho | 1.7% | — |
| CVE-2014-2107 | HIGH 7.1 | cisco ios Cisco IOS 12.2 and 15.0 through 15.3, when used with the Kailash FPGA before 2.6 on RSP720-3C-10GE and RSP720-3CXL-10GE devices, allows remote attackers to cause a denial of service (route switch processor outage) via crafted IP packets, aka Bug ID CSCug84789. | 1.7% | — |
| CVE-2013-6941 | HIGH 10.0 | citrix netscaler_application_delivery_controller_firmware Unspecified vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows users to "breakout" of the shell via unknown vectors. | 1.7% | — |
| CVE-2014-0718 | HIGH 7.1 | cisco ips_sensor_software The produce-verbose-alert feature in Cisco IPS Software 7.1 before 7.1(8)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of service (Analysis Engine process outage) via fragmented packets, aka Bug ID CSCui91266. | 1.7% | — |
| CVE-2013-5549 | HIGH 7.1 | cisco ios_xr Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B route-processor components, which allows remote attackers to cause a denial of service (transmission outage) via (1) IPv4 or (2) IPv6 traffic, a | 1.7% | — |
| CVE-2007-2032 | HIGH 7.5 | cisco wireless_control_system Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to "properties of the FTP server," aka Bug ID | 1.7% | — |
| CVE-2004-2365 | LOW 2.1 | microsoft windows_2003_server Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of service (memory exhaustion) by repeatedly creating and deleting directories using a non-standard tool such as smbmount. | 1.7% | — |
| CVE-2025-21355 | HIGH 8.6 | microsoft bing Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network | 1.7% | — |
| CVE-2024-37342 | HIGH 7.1 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | 1.7% | — |
| CVE-2024-37337 | HIGH 7.1 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | 1.7% | — |
| CVE-2023-28297 | HIGH 8.8 | microsoft windows_10_1607 Windows Remote Procedure Call Service (RPCSS) Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2022-20799 | MED 4.7 | cisco rv340_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. Thes | 1.7% | — |
| CVE-2021-1555 | MED 4.7 | cisco wap125_firmware Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These | 1.7% | — |
| CVE-2021-1553 | MED 4.7 | cisco wap125_firmware Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These | 1.7% | — |
| CVE-2021-1552 | MED 4.7 | cisco wap125_firmware Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These | 1.7% | — |