57.255 CVE tracked
779 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.255 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-16999 | MED 5.5 | microsoft windows_10 Windows WalletService Information Disclosure Vulnerability | 1.3% | — |
| CVE-2020-14386 | MED 6.7 | debian debian_linux A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity. | 1.3% | — |
| CVE-2018-13371 | HIGH 8.8 | fortinet fortios An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via connecting to the ZebOS component. | 1.3% | — |
| CVE-2020-0775 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Information Disclosu | 1.3% | — |
| CVE-2019-6650 | CRIT 9.1 | f5 big-ip_application_security_manager F5 BIG-IP ASM 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 may expose sensitive information and allow the system configuration to be modified when using non-default settings. | 1.3% | — |
| CVE-2019-1294 | MED 4.6 | microsoft windows_10 A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'. | 1.3% | — |
| CVE-2016-3300 | HIGH 7.8 | microsoft windows_8.1 The Netlogon service in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 improperly establishes secure communications channels, which allows local users to gain privileges by leveraging access to a domain-joined machine, aka "Netlogon | 1.3% | — |
| CVE-2012-0331 | HIGH 7.5 | cisco telepresence_system_software Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP packet, as demonstrated by a SIP INVITE message from a Tandberg device, aka Bug ID CSCtq73319. | 1.3% | — |
| CVE-2021-31982 | HIGH 8.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2021-34704 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerabili | 1.3% | — |
| CVE-2021-1573 | HIGH 8.6 | cisco adaptive_security_appliance A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerabili | 1.3% | — |
| CVE-2020-3391 | MED 6.5 | cisco digital_network_architecture_center A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to insecure storage of certain unencrypted credentials on an affected device. | 1.3% | — |
| CVE-2020-1194 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists when Windows Registry improperly handles filesystem operations, aka 'Windows Registry Denial of Service Vulnerability'. | 1.3% | — |
| CVE-2020-0859 | MED 5.5 | microsoft windows_10 An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'. | 1.3% | — |
| CVE-2020-0643 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI+ Information Disclosure Vulnerabil | 1.3% | — |
| CVE-2020-0639 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. This CVE ID is unique from | 1.3% | — |
| CVE-2020-0608 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. | 1.3% | — |
| CVE-2018-1035 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows 10, Windows 10 Servers. | 1.3% | — |
| CVE-2009-4455 | MED 6.5 | cisco adaptive_security_appliance_5500 The default configuration of Cisco ASA 5500 Series Adaptive Security Appliance (Cisco ASA) 7.0, 7.1, 7.2, 8.0, 8.1, and 8.2 allows portal traffic to access arbitrary backend servers, which might allow remote authenticated users to bypass intended access restri | 1.3% | — |
| CVE-2002-0880 | MED 5.0 | cisco skinny_client_control_protocol_software Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", an | 1.3% | — |
| CVE-2023-50270 | MED 6.5 | apache dolphinscheduler Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue. | 1.3% | — |
| CVE-2019-15983 | MED 4.9 | cisco data_center_network_manager A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an attacker would need administrat | 1.3% | — |
| CVE-2019-12706 | HIGH 7.5 | cisco email_security_appliance_firmware A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the configured user filters on an affected device. The vulnerability | 1.3% | — |
| CVE-2012-6596 | MED 5.0 | paloaltonetworks pan-os Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.3 stores cleartext LDAP bind passwords in authd.log, which allows context-dependent attackers to obtain sensitive information by reading this file, aka Ref ID 35493. | 1.3% | — |
| CVE-1999-0998 | MED 5.0 | cisco cache_engine Cisco Cache Engine allows an attacker to replace content in the cache. | 1.3% | — |