57.411 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.411 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1535 | MED 5.3 | cisco sd-wan_vmanage A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. To be affected by this vulnerability, the Cisco SD-WAN vManage Software mu | 1.2% | — |
| CVE-2020-3461 | MED 5.3 | cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. The vulnerability is due to missing authentication on | 1.2% | — |
| CVE-2020-12654 | HIGH 7.1 | linux linux_kernel An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wmm.c allows a remote AP to trigger a heap-based buffer overflow because of an incorrect memcpy, aka CID-3a9b153c5591. | 1.2% | — |
| CVE-2018-0816 | HIGH 7.0 | microsoft windows_10 The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 al | 1.2% | — |
| CVE-2018-0109 | LOW 2.7 | cisco webex_meetings_server A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to obtain information to conduct additional reconnaissance attacks. The vu | 1.2% | — |
| CVE-2015-0746 | MED 5.0 | cisco secure_access_control_server The REST API in Cisco Access Control Server (ACS) 5.5(0.46.2) allows remote attackers to cause a denial of service (API outage) by sending many requests, aka Bug ID CSCut62022. | 1.2% | — |
| CVE-2015-0712 | MED 5.0 | cisco staros The session-manager service in Cisco StarOS 12.0, 12.2(300), 14.0, and 14.0(600) on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and packet loss) via malformed HTTP packets, aka Bug ID CSCud14217. | 1.2% | — |
| CVE-2015-0657 | MED 5.0 | cisco ios_xr Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCur69192. | 1.2% | — |
| CVE-2015-0605 | MED 4.3 | cisco asyncos The uuencode inspection engine in Cisco AsyncOS on Cisco Email Security Appliance (ESA) devices 8.5 and earlier allows remote attackers to bypass intended content restrictions via a crafted e-mail attachment with uuencode encoding, aka Bug ID CSCzv54343. | 1.2% | — |
| CVE-2014-8014 | MED 5.0 | cisco ios_xr Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCub63710. | 1.2% | — |
| CVE-2014-3268 | MED 5.0 | cisco ios Cisco IOS 15.2(4)M4 on Cisco Unified Border Element (CUBE) devices allows remote attackers to cause a denial of service (input-queue consumption and traffic-processing outage) via crafted RTCP packets, aka Bug ID CSCuj72215. | 1.2% | — |
| CVE-2012-4079 | MED 5.0 | cisco unified_computing_system The XML API service in the Fabric Interconnect component in Cisco Unified Computing System (UCS) allows remote attackers to cause a denial of service (API service outage) via a malformed XML document in a packet, aka Bug ID CSCtg48206. | 1.2% | — |
| CVE-2012-3446 | MED 5.9 | apache libcloud Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attac | 1.2% | — |
| CVE-2012-3919 | MED 5.0 | cisco application_control_engine_module The Cisco Application Control Engine (ACE) module 3.0 for Cisco Catalyst switches and Cisco routers does not properly monitor Load Balancer (LB) queues, which allows remote attackers to cause a denial of service (incorrect memory access and module reboot) via | 1.2% | — |
| CVE-2012-3915 | MED 5.0 | cisco ios The DMVPN tunnel implementation in Cisco IOS 15.2 allows remote attackers to cause a denial of service (persistent IKE state) via a large volume of hub-to-spoke traffic, aka Bug ID CSCtq39602. | 1.2% | — |
| CVE-2012-3901 | MED 5.0 | cisco intrusion_prevention_system The updateTime function in sensorApp on Cisco IPS 4200 series sensors 7.0 and 7.1 allows remote attackers to cause a denial of service (process crash and traffic-inspection outage) via network traffic, aka Bug ID CSCta96144. | 1.2% | — |
| CVE-2012-1339 | MED 5.0 | cisco unified_computing_system_infrastructure_and_unified_computing_system_software The Fabric Interconnect component in Cisco Unified Computing System (UCS) 2.0 allows remote attackers to cause a denial of service (process crash) via an attempted SSH session, aka Bug ID CSCtt94543. | 1.2% | — |
| CVE-2012-0376 | MED 5.0 | cisco unified_communications_manager The voice-sipstack component in Cisco Unified Communications Manager (CUCM) 8.5 allows remote attackers to cause a denial of service (core dump) via vectors involving SIP messages that arrive after an upgrade, aka Bug ID CSCtj87367. | 1.2% | — |
| CVE-2003-1454 | MED 5.0 | invision_power_services invision_board Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access. | 1.2% | — |
| CVE-2023-35333 | HIGH 8.8 | microsoft pandocupload MediaWiki PandocUpload Extension Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2017-5652 | HIGH 7.5 | apache impala During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when the cluster was configured to use TLS. The port in question was used by the StatestoreSubscriber class which di | 1.2% | — |
| CVE-2015-6368 | MED 5.0 | cisco firepower_extensible_operating_system Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608. | 1.2% | — |
| CVE-2012-4074 | MED 5.8 | cisco unified_computing_system The Board Management Controller (BMC) in the Serial over LAN (SoL) subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded private key, which allows man-in-the-middle attackers to obtain sensitive information or modify the data stream by levera | 1.2% | — |
| CVE-2021-1509 | HIGH 7.5 | cisco vedge_1000_firmware Multiple vulnerabilities in Cisco SD-WAN vEdge Software could allow an attacker to execute arbitrary code as the root user or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details sec | 1.2% | — |
| CVE-2020-17134 | HIGH 7.8 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 1.2% | — |