57.061 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.061 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-10139 | MED 6.1 | paloaltonetworks pan-os The PAN-OS response for GlobalProtect Gateway in Palo Alto Networks PAN-OS 6.1.21 and earlier, PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML. PAN-OS 8.1 is NOT affected. | 1.5% | — |
| CVE-2010-1987 | MED 5.0 | mozilla firefox Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption, out-of-bounds read, and application crash) via JavaScript code that appends long strings to the content of a P element, and performs certain other | 1.5% | — |
| CVE-2016-9251 | HIGH 8.8 | f5 big-ip_access_policy_manager In F5 BIG-IP 12.0.0 through 12.1.2, an authenticated attacker may be able to cause an escalation of privileges through a crafted iControl REST connection. | 1.5% | — |
| CVE-2019-16027 | MED 6.5 | cisco ios_xr A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition | 1.5% | — |
| CVE-2019-12714 | MED 6.5 | cisco ic3000_industrial_compute_gateway_firmware A vulnerability in the web-based management interface of Cisco IC3000 Industrial Compute Gateway could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected sof | 1.5% | — |
| CVE-2019-6646 | HIGH 8.8 | f5 big-ip_access_policy_manager On BIG-IP 11.5.2-11.6.4 and Enterprise Manager 3.1.1, REST users with guest privileges may be able to escalate their privileges and run commands with admin privileges. | 1.5% | — |
| CVE-2019-1884 | HIGH 7.7 | cisco asyncos A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insuff | 1.5% | — |
| CVE-2018-0854 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Windows Scripting Host which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is | 1.5% | — |
| CVE-2015-6384 | MED 4.3 | cisco webex_meetings The Cisco WebEx Meetings application before 8.5.1 for Android improperly initializes custom application permissions, which allows attackers to bypass intended access restrictions via a crafted application, aka Bug ID CSCuw86442. | 1.5% | — |
| CVE-2014-8580 | MED 4.9 | citrix netscaler_application_delivery_controller_firmware Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5.50.10 before 10.5-52.11, 10.1.122.17 before 10.1-129.11, and 10.1-120.1316.e before 10.1-129.1105.e, when using unspecified configurations, allows remote authenticated users to access | 1.5% | — |
| CVE-2014-0655 | MED 4.3 | cisco adaptive_security_appliance The Identity Firewall (IDFW) functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to change the user-cache contents via a replay attack involving crafted RADIUS Change of Authorization (CoA) messages, aka Bug ID CSCuj45332. | 1.5% | — |
| CVE-2012-2975 | MED 4.3 | f5 application_security_manager_appliance Cross-site scripting (XSS) vulnerability in the traffic overview page on the F5 ASM appliance 10.0.0 through 11.2.0 HF2 allows remote attackers to inject arbitrary web script or HTML via crafted requests that are later listed on a summary page. | 1.5% | — |
| CVE-2025-26686 | HIGH 7.5 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | 1.5% | — |
| CVE-2024-53299 | MED 6.5 | apache wicket The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which fixes this issue. | 1.5% | — |
| CVE-2021-33850 | MED 5.4 | microsoft clarity There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the user changes the clarity configuration in Microsoft Clarity version 0.3. The payload is stored on the configuring project Id page. | 1.5% | — |
| CVE-2017-10618 | MED 5.9 | juniper junos When the 'bgp-error-tolerance' feature â€" designed to help mitigate remote session resets from malformed path attributes â€" is enabled, a BGP UPDATE containing a specifically crafted set of transitive attributes can cause the RPD routing | 1.5% | — |
| CVE-2017-0098 | MED 5.4 | microsoft windows_10 Hyper-V in Microsoft Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is diffe | 1.5% | — |
| CVE-2020-3407 | HIGH 8.6 | cisco ios_xe A vulnerability in the RESTCONF and NETCONF-YANG access control list (ACL) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect processing of the ACL that is tied | 1.5% | — |
| CVE-2019-5774 | HIGH 8.8 | debian debian_linux Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file. | 1.5% | — |
| CVE-2018-15389 | CRIT 9.8 | cisco prime_collaboration A vulnerability in the install function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the administrative web interface using a default hard-coded username and password that are used during install. Th | 1.5% | — |
| CVE-2022-36125 | HIGH 7.5 | apache avro It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addr | 1.5% | — |
| CVE-2022-0024 | HIGH 7.2 | paloaltonetworks pan-os A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-based PAN-OS administrator to upload a specifically created configuration that disrupts system processes and potentially execute arbitrary code with root privile | 1.5% | — |
| CVE-2021-31964 | HIGH 7.6 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1.5% | — |
| CVE-2020-3359 | HIGH 8.6 | cisco ios_xe A vulnerability in the multicast DNS (mDNS) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper | 1.5% | — |
| CVE-2020-3221 | HIGH 8.6 | cisco ios_xe A vulnerability in the Flexible NetFlow Version 9 packet processor of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. | 1.5% | — |