57.139 CVE tracked
779 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.139 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-1999-1370 | HIGH 7.2 | microsoft internet_explorer The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prev | 1.3% | — |
| CVE-2023-27874 | CRIT 9.9 | ibm aspera_faspex IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845. | 1.3% | — |
| CVE-2021-41832 | HIGH 7.5 | apache openoffice It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25635 for the LibreOffice advisory. | 1.3% | — |
| CVE-2021-23015 | HIGH 7.2 | f5 big-ip_access_policy_manager On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an authenticated user assigned the 'Administrator' role may be able to bypass Appliance Mode restrictions utilizing u | 1.3% | — |
| CVE-2005-0921 | MED 4.6 | microsoft outlook_connector Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy. | 1.3% | — |
| CVE-2023-32042 | MED 6.5 | microsoft windows_10_1507 OLE Automation Information Disclosure Vulnerability | 1.3% | — |
| CVE-2018-0044 | CRIT 9.8 | juniper junos An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remote unauthenticated access if any of the passwords on the system are empty. The affected SSHD configuration has the PermitEmptyPasswords optio | 1.3% | — |
| CVE-2017-5106 | MED 6.5 | debian debian_linux Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name. | 1.3% | — |
| CVE-2017-5105 | MED 6.5 | debian debian_linux Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name. | 1.3% | — |
| CVE-2013-5531 | MED 5.0 | cisco identity_services_engine_software Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and credentials data, via a crafted session on TCP port 443, aka Bug ID CSCty20405. | 1.3% | — |
| CVE-2003-0897 | MED 4.6 | microsoft windows_xp "Shatter" vulnerability in CommCtl32.dll in Windows XP may allow local users to execute arbitrary code by sending (1) BCM_GETTEXTMARGIN or (2) BCM_SETTEXTMARGIN button control messages to privileged applications. | 1.3% | — |
| CVE-2024-45784 | HIGH 7.5 | apache airflow Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentionally or intentionally log sensitive configuration variables. Unauthorized users | 1.3% | — |
| CVE-2024-43583 | HIGH 7.8 | microsoft windows_10_1507 Winlogon Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2024-27140 | MED 5.4 | apache archiva ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva. This issue affects Apache Archiva: from 2.0.0. As this project is retired, we do not plan to release a vers | 1.3% | — |
| CVE-2023-22275 | HIGH 7.5 | adobe robohelp_server Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this | 1.3% | — |
| CVE-2021-1501 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a | 1.3% | — |
| CVE-2021-1364 | MED 6.5 | cisco unified_communications_manager Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities | 1.3% | — |
| CVE-2021-1282 | MED 6.5 | cisco unified_communications_manager Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities | 1.3% | — |
| CVE-2011-4650 | HIGH 7.5 | cisco data_center_network_manager Cisco Data Center Network Manager is affected by Excessive Logging During a TCP Flood on Java Ports. If the size of server.log becomes very big because of too much logging by the DCNM server, then the CPU utilization increases. Known Affected Releases: 5.2(1). | 1.3% | — |
| CVE-2015-6409 | MED 5.9 | cisco jabber Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419. | 1.3% | — |
| CVE-2007-2033 | MED 6.5 | cisco wireless_control_system Unspecified vulnerability in Cisco Wireless Control System (WCS) before 4.0.81.0 allows remote authenticated users to read any configuration page by changing the group membership of user accounts, aka Bug ID CSCse78596. | 1.3% | — |
| CVE-2026-21243 | HIGH 7.5 | microsoft windows_server_2019 Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | 1.3% | — |
| CVE-2026-20846 | HIGH 7.5 | microsoft windows_10_1607 Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. | 1.3% | — |
| CVE-2019-4377 | MED 4.3 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in further attacks against the system. IBM X-Force ID: 162803. | 1.3% | — |
| CVE-2017-4939 | HIGH 7.8 | vmware workstation VMware Workstation (12.x before 12.5.8) installer contains a DLL hijacking issue that exists due to some DLL files loaded by the application improperly. This issue may allow an attacker to load a DLL file of the attacker's choosing that could execute arbitrary | 1.3% | — |