57.075 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.075 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2006-5416 | MED 5.1 | f5 firepass_1000 Cross-site scripting (XSS) vulnerability in my.acctab.php3 in F5 Networks FirePass 1000 SSL VPN 5.5, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the sid parameter. | 1.5% | — |
| CVE-2001-0350 | MED 4.6 | microsoft windows_2000 Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program wi | 1.5% | — |
| CVE-2024-23807 | CRIT 9.8 | apache xerces-c\+\+ The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD pro | 1.5% | — |
| CVE-2023-28983 | HIGH 8.8 | juniper junos_os_evolved An OS Command Injection vulnerability in gRPC Network Operations Interface (gNOI) server module of Juniper Networks Junos OS Evolved allows an authenticated, low privileged, network based attacker to inject shell commands and execute code. This issue affects J | 1.5% | — |
| CVE-2021-20373 | HIGH 7.5 | ibm db2 IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521. | 1.5% | — |
| CVE-2020-3926 | MED 6.1 | changingtec servisign An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter. | 1.5% | — |
| CVE-2019-1486 | MED 6.1 | microsoft visual_studio_2019 A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'. | 1.5% | — |
| CVE-2019-12292 | CRIT 9.8 | citrix appdna Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control. | 1.5% | — |
| CVE-2019-9548 | CRIT 10.0 | citrix application_delivery_management Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control. | 1.5% | — |
| CVE-2018-0397 | MED 5.9 | cisco advanced_malware_protection_for_endpoints A vulnerability in Cisco AMP for Endpoints Mac Connector Software installed on Apple macOS 10.12 could allow an unauthenticated, remote attacker to cause a kernel panic on an affected system, resulting in a denial of service (DoS) condition. The vulnerability | 1.5% | — |
| CVE-2013-1223 | HIGH 7.8 | cisco unified_customer_voice_portal The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly validate an unspecified parameter, which allows remote attackers to read arbitrary files via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub3837 | 1.5% | — |
| CVE-2010-3033 | HIGH 9.0 | cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different v | 1.5% | — |
| CVE-2010-2843 | HIGH 9.0 | cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different v | 1.5% | — |
| CVE-2010-2842 | HIGH 9.0 | cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different v | 1.5% | — |
| CVE-2021-40727 | HIGH 7.8 | adobe indesign Access of Memory Location After End of Buffer (CWE-788 | 1.5% | — |
| CVE-2020-4879 | CRIT 9.8 | ibm cognos_controller IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847. | 1.5% | — |
| CVE-1999-0628 | MED 5.0 | freebsd freebsd The rwho/rwhod service is running, which exposes machine status and user information. | 1.5% | — |
| CVE-2022-20714 | HIGH 8.6 | cisco ios_xr A vulnerability in the data plane microcode of Lightspeed-Plus line cards for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the line card to reset. This vulnerability is due to the incorrect handlin | 1.5% | — |
| CVE-2021-27193 | CRIT 9.8 | netop vision_pro Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation. | 1.5% | — |
| CVE-2019-1640 | HIGH 7.8 | cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1.5% | — |
| CVE-2019-1639 | HIGH 7.8 | cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1.5% | — |
| CVE-2019-1638 | HIGH 7.8 | cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1.5% | — |
| CVE-2019-1637 | HIGH 7.8 | cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1.5% | — |
| CVE-2017-2493 | MED 6.5 | apple icloud An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to byp | 1.5% | — |
| CVE-2011-0244 | MED 4.3 | apple safari WebKit in Apple Safari before 5.0.6 allows user-assisted remote attackers to read arbitrary files via vectors related to improper canonicalization of URLs within RSS feeds. | 1.5% | — |