57.080 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.080 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1925 | HIGH 7.8 | cisco webex_business_suite Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software | 1.5% | — |
| CVE-2017-7738 | HIGH 7.2 | fortinet fortios An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_admin privileges to view the current SSL VPN web portal session info which may contains user credentials through t | 1.5% | — |
| CVE-2011-4012 | HIGH 9.3 | cisco ios Cisco IOS 12.0, 15.0, and 15.1, when a Policy Feature Card 3C (PFC3C) is used, does not create a fragment entry during processing of an ICMPv6 ACL, which has unspecified impact and remote attack vectors, aka Bug ID CSCtj90091. | 1.5% | — |
| CVE-2009-3485 | MED 4.3 | juniper junos Cross-site scripting (XSS) vulnerability in the J-Web interface in Juniper JUNOS 8.5R1.14 and 9.0R1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI. | 1.5% | — |
| CVE-2008-2030 | MED 4.3 | f5 firepass_4100 Cross-site scripting (XSS) vulnerability in installControl.php3 in F5 FirePass 4100 SSL VPN 5.4.2-5.5.2 and 6.0-6.2 allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: the provenance of this information is unknown; the d | 1.5% | — |
| CVE-1999-0344 | HIGH 7.2 | microsoft windows_nt NT users can gain debug-level access on a system process using the Sechole exploit. | 1.5% | — |
| CVE-2025-49656 | HIGH 7.5 | apache jena Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue. | 1.5% | — |
| CVE-2024-26180 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.5% | — |
| CVE-2022-21929 | LOW 2.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2020-26078 | MED 6.5 | cisco iot_field_network_director A vulnerability in the file system of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to overwrite files on an affected system. The vulnerability is due to insufficient file system protections. An attacker could exploit thi | 1.5% | — |
| CVE-2017-0219 | MED 5.3 | microsoft windows_10 Microsoft Windows 10 Gold, Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, | 1.5% | — |
| CVE-2017-0216 | MED 5.3 | microsoft windows_10 Microsoft Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard | 1.5% | — |
| CVE-2017-0173 | MED 5.3 | microsoft windows_10 Microsoft Windows 10 1607 and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Po | 1.5% | — |
| CVE-2017-2321 | HIGH 8.6 | juniper northstar_controller A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modification of | 1.5% | — |
| CVE-2017-3880 | MED 6.5 | cisco webex_meetings_server An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access limited meeting information on the Cisco WebEx Meetings Server. More Information: CSCvd50728. Known Affected Releases: 2.6 2.7 2.8 C | 1.5% | — |
| CVE-2015-1234 | MED 6.8 | google chrome Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact by manipulating OpenGL ES commands. | 1.5% | — |
| CVE-2022-30670 | HIGH 8.8 | adobe robohelp_server RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalation. An authenticated attacker could leverage this vulnerability to achieve full administrator privileges. Exploi | 1.5% | — |
| CVE-2020-7819 | CRIT 9.3 | ntracker ntracker_usb_enterprise A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. | 1.5% | — |
| CVE-2021-1378 | MED 5.3 | cisco staros A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to a logi | 1.5% | — |
| CVE-2019-1657 | MED 4.3 | cisco amp_threat_grid_appliance A vulnerability in Cisco AMP Threat Grid could allow an authenticated, remote attacker to access sensitive information. The vulnerability is due to unsafe creation of API keys. An attacker could exploit this vulnerability by using insecure credentials to gain | 1.5% | — |
| CVE-2016-8394 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged p | 1.5% | — |
| CVE-2008-7037 | HIGH 7.5 | itn itn_news_gadget The Sidebar gadget in ITN News Gadget (aka ITN Hub Gadget) 1.06 for Windows Vista, and possibly other versions before 1.23, allows remote web servers or man-in-the-middle attackers to execute arbitrary commands via script in a short_title response. | 1.5% | — |
| CVE-2023-51387 | HIGH 7.2 | apache hertzbeat Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. The alert expressions are supposed to be some simple expressions. However, due to improper sanitization for alert expressions in version prior | 1.4% | — |
| CVE-2021-42323 | LOW 3.3 | microsoft azure_real_time_operating_system Azure RTOS Information Disclosure Vulnerability | 1.4% | — |
| CVE-2018-1000420 | MED 6.5 | apache mesos An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins. | 1.4% | — |