57.415 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.415 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-20164 | MED 6.5 | cisco identity_services_engine Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must ha | 1.2% | — |
| CVE-2023-20163 | MED 6.5 | cisco identity_services_engine Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must ha | 1.2% | — |
| CVE-2023-21799 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-21798 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-21797 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-41617 | HIGH 7.2 | f5 big-ip_advanced_web_application_firewall In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is provisioned, an authenticated remote code execution vulnerability exists in the BIG-IP iControl REST interface | 1.2% | — |
| CVE-2021-1614 | MED 5.3 | cisco sd-wan A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to gain access to information stored in MPLS buffer memory. This vulnerability is due to insufficient | 1.2% | — |
| CVE-2021-1422 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker or an unauthenticated attacker in a man-in-the-middle positi | 1.2% | — |
| CVE-2013-1279 | HIGH 7.2 | microsoft windows_7 Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges | 1.2% | — |
| CVE-2026-35424 | HIGH 7.5 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2024-20673 | HIGH 7.8 | microsoft excel Microsoft Office Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-46749 | MED 6.5 | apache shiro Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+, or ensure `blockSemicolon | 1.2% | — |
| CVE-2023-28406 | MED 4.3 | f5 big-ip_access_policy_manager A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control wha | 1.2% | — |
| CVE-2021-34703 | MED 6.8 | cisco ios A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and Cisco IOS XE Software could allow an attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability i | 1.2% | — |
| CVE-2021-34699 | HIGH 7.7 | cisco ios A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to an improper interaction between the web UI and the CLI parser. A | 1.2% | — |
| CVE-2014-8006 | MED 4.3 | cisco isb8320-e_high-definition_ip-only_dvr The Disaster Recovery (DRA) feature on the Cisco ISB8320-E High-Definition IP-Only DVR allows remote attackers to bypass authentication by establishing a TELNET session during a recovery boot, aka Bug ID CSCup85422. | 1.2% | — |
| CVE-2013-3426 | MED 5.0 | cisco unified_ip_phone_9951 The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specifying a pathname in a file request, aka Bug ID CSCuh52810. | 1.2% | — |
| CVE-2023-35619 | MED 5.3 | microsoft office_long_term_servicing_channel Microsoft Outlook for Mac Spoofing Vulnerability | 1.2% | — |
| CVE-2022-34709 | MED 6.0 | microsoft windows_10 Windows Defender Credential Guard Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2022-31769 | MED 5.3 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration information stored in PostgreSQL, which could be used in further attacks against the system. IBM X-Force ID: 228219. | 1.2% | — |
| CVE-2021-40782 | MED 5.5 | adobe media_encoder Adobe Media Encoder 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of | 1.2% | — |
| CVE-2021-40774 | MED 5.5 | adobe prelude Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of | 1.2% | — |
| CVE-2021-40773 | MED 5.5 | adobe prelude Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of | 1.2% | — |
| CVE-2019-1627 | MED 6.5 | cisco integrated_management_controller A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on the affected system. T | 1.2% | — |
| CVE-2014-2184 | MED 5.0 | cisco unified_communications_manager The IP Manager Assistant (IPMA) component in Cisco Unified Communications Manager (Unified CM) allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCun74352. | 1.2% | — |