57.298 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.298 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-1450 | HIGH 7.5 | cisco webex_meetings_server Cisco WebEx Meetings Server 2.6 allows remote authenticated users to conduct command-injection attacks via vectors related to an upload's file type, aka Bug ID CSCuy92715. | 1.3% | — |
| CVE-2015-0620 | MED 4.0 | cisco telepresence_management_suite The XML parser in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier does not properly handle external entities, which allows remote authenticated users to cause a denial of service via POST requests, aka Bug ID CSCus51494. | 1.3% | — |
| CVE-2021-1366 | HIGH 7.8 | cisco anyconnect_secure_mobility_client A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is | 1.3% | — |
| CVE-2020-16921 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists in Text Services Framework when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could potentially read data that was not intended to be disclosed. Note t | 1.3% | — |
| CVE-2020-16919 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows Enterprise App Management Service improperly handles certain file operations. An attacker who successfully exploited this vulnerability could read arbitrary files.</p> <p>An attacker with unpri | 1.3% | — |
| CVE-2018-1009 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles objects in memory and incorrectly maps kernel memory, aka "Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Wi | 1.3% | — |
| CVE-2015-0741 | MED 6.8 | cisco hosted_collaboration_solution Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS) 10.6(1) and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut04596. | 1.3% | — |
| CVE-2015-0740 | MED 6.8 | cisco unified_intelligence_center Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center 10.6(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus28826. | 1.3% | — |
| CVE-2026-50330 | HIGH 7.5 | microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network. | 1.3% | — |
| CVE-2022-34883 | HIGH 7.2 | hitachi raid_manager_storage_replication_adapter OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to execute arbitrary OS commands. This issue affects: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versions prior to 02.03.02 | 1.3% | — |
| CVE-2006-4352 | MED 5.0 | cisco content_services_switch_11000 The ArrowPoint cookie functionality for Cisco 11000 series Content Service Switches specifies an internal IP address if the administrator does not specify a string option, which allows remote attackers to obtain sensitive information. | 1.3% | — |
| CVE-2022-30200 | HIGH 7.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2019-4576 | CRIT 9.8 | ibm qradar_network_packet_capture IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166803. | 1.3% | — |
| CVE-2019-17366 | HIGH 8.8 | citrix application_delivery_management Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control. | 1.3% | — |
| CVE-2016-1440 | MED 5.3 | cisco web_security_appliance The proxy process on Cisco Web Security Appliance (WSA) devices through 9.1.0-070 allows remote attackers to cause a denial of service (CPU consumption) by establishing an FTP session and then improperly terminating the control connection after a file transfer | 1.3% | — |
| CVE-2007-5473 | MED 5.0 | mono mono StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitive files via a request containing a trailing (1) space or (2) dot, which is not properly handled by XSP. | 1.3% | — |
| CVE-2024-29050 | HIGH 8.4 | microsoft windows_10_1507 Windows Cryptographic Services Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2022-43717 | MED 5.4 | apache superset Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vectors that can be performed by authenticated users with create dashboard permissions. This issue affects Apache Superset version 1.5.2 and pr | 1.3% | — |
| CVE-2018-8592 | MED 6.4 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD, etc, aka "Windows Elevation Of Privilege Vulnerability." This affects Windows 10, Windows Server 2019. | 1.3% | — |
| CVE-2026-20803 | HIGH 7.2 | microsoft sql_server_2022 Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.2% | — |
| CVE-2022-33636 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2020-7882 | HIGH 7.5 | hancom anysign4pc Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../') | 1.2% | — |
| CVE-2020-35112 | HIGH 8.8 | mozilla firefox If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable w | 1.2% | — |
| CVE-2017-7342 | CRIT 9.8 | fortinet fortiportal A weak password recovery process vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via a hidden Close button | 1.2% | — |
| CVE-2019-1669 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies or cause a denial of service (DoS) condition. The vulnerabilit | 1.2% | — |