57.139 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.139 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-8035 | MED 5.0 | cisco webex_meetings_server The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requests, aka Bug ID CSCuj40247. | 1.4% | — |
| CVE-2014-3281 | MED 5.0 | cisco unified_communications_domain_manager The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attackers to obtain potentially sensitive user information by visiting an unspecified BVSMWeb web page, aka Bug IDs C | 1.4% | — |
| CVE-2014-3278 | MED 5.0 | cisco unified_communications_domain_manager The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attackers to enumerate accounts by visiting an unspecified BVSMWeb web page, aka Bug IDs CSCun39619 and CSCun45572. | 1.4% | — |
| CVE-2013-5502 | MED 5.0 | cisco mediasense The web interface in Cisco MediaSense does not properly protect the client-server communication channel, which allows remote attackers to obtain sensitive query string or cookie information via unspecified vectors, aka Bug ID CSCuj23344. | 1.4% | — |
| CVE-2013-5489 | MED 5.0 | cisco socialminer The gadget implementation in Cisco SocialMiner does not properly restrict the content of GET requests, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, | 1.4% | — |
| CVE-2023-36887 | HIGH 7.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2022-31179 | HIGH 8.1 | shescape_project shescape Shescape is a simple shell escape package for JavaScript. Versions prior to 1.5.8 were found to be subject to code injection on windows. This impacts users that use Shescape (any API function) to escape arguments for cmd.exe on Windows An attacker can omit all | 1.4% | — |
| CVE-2020-8247 | HIGH 8.8 | citrix application_delivery_controller_firmware Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WA | 1.4% | — |
| CVE-2020-1351 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. | 1.4% | — |
| CVE-2017-5079 | MED 4.3 | google chrome Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page. | 1.4% | — |
| CVE-2017-5046 | MED 4.3 | debian debian_linux V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android had insufficient policy enforcement, which allowed a remote attacker to spoof the location object via a crafted HTML page, related to Blink information disclosu | 1.4% | — |
| CVE-2013-1188 | MED 5.0 | cisco unified_communications_manager Cisco Unified Communications Manager (CUCM) does not properly limit the rate of authentication attempts, which allows remote attackers to cause a denial of service (application slowdown) via a series of requests, aka Bug ID CSCud39515. | 1.4% | — |
| CVE-2010-3718 | LOW 1.2 | apache tomcat Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstra | 1.4% | — |
| CVE-2009-0082 | HIGH 7.8 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions, | 1.4% | — |
| CVE-2007-0188 | MED 6.5 | f5 firepass F5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP address ("dotless IP address"), which allows remote authenticated users to connect to the FirePass administrato | 1.4% | — |
| CVE-2021-38639 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2021-1357 | MED 6.5 | cisco unified_communications_manager Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities | 1.4% | — |
| CVE-2021-1355 | MED 6.5 | cisco unified_communications_manager Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities | 1.4% | — |
| CVE-2021-1242 | MED 4.3 | cisco webex_teams A vulnerability in Cisco Webex Teams could allow an unauthenticated, remote attacker to manipulate file names within the messaging interface. The vulnerability exists because the affected software mishandles character rendering. An attacker could exploit this | 1.4% | — |
| CVE-2019-1039 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory. To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vul | 1.4% | — |
| CVE-2018-14735 | HIGH 7.5 | hitachi command_suite An Information Exposure issue was discovered in Hitachi Command Suite 8.5.3. A remote attacker may be able to exploit a flaw in the permission of messaging that may allow for information exposure via a crafted message. | 1.4% | — |
| CVE-2017-6680 | HIGH 7.5 | cisco ultra_services_framework A vulnerability in the AutoVNF logging function of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to create arbitrary directories on the affected system. More Information: CSCvc76652. Known Affected Releases: 21.0.0. | 1.4% | — |
| CVE-2015-8021 | MED 4.3 | f5 big-ip_access_policy_manager Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; BIG-IP AAM 11.4.0 before HF8 and 11.4.1 before HF6; | 1.4% | — |
| CVE-2015-0715 | MED 6.5 | cisco unity_connection SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug IDs CSCut33447 and CSCut33608. | 1.4% | — |
| CVE-2015-0684 | MED 6.5 | cisco unified_communications_domain_manager SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq52515. | 1.4% | — |