57.415 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.415 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-5538 | MED 5.0 | cisco identity_services_engine The Sponsor Portal in Cisco Identity Services Engine (ISE) uses weak permissions for uploaded files, which allows remote attackers to read arbitrary files via a direct request, aka Bug ID CSCui67506. | 1.2% | — |
| CVE-2013-3398 | MED 5.0 | cisco prime_central_for_hosted_collaboration_solution The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance provides different responses to requests for arbitrary pathnames depending on whether the pathname exists, which allows remote attackers to enumerate directories and fil | 1.2% | — |
| CVE-2013-1232 | MED 5.0 | cisco webex_meetings_server The HTTP implementation in Cisco WebEx Node for MCS, WebEx Meetings Server, and WebEx Node for ASR 1000 Series allows remote attackers to read the contents of uninitialized memory locations via a crafted request, aka Bug IDs CSCue36672, CSCue31363, CSCuf17466, | 1.2% | — |
| CVE-2013-1231 | MED 5.0 | cisco webex_meetings_server The HTTP implementation in Cisco WebEx Node for MCS and WebEx Meetings Server allows remote attackers to read cache files via a crafted request, aka Bug IDs CSCue36664 and CSCue36629. | 1.2% | — |
| CVE-2013-1214 | MED 5.0 | cisco unified_contact_center_express_editor_software The scripts editor in Cisco Unified Contact Center Express (aka Unified CCX) does not properly manage privileges for anonymous logins, which allows remote attackers to read arbitrary scripts by visiting the scripts repository directory, aka Bug ID CSCuf77546. | 1.2% | — |
| CVE-2012-1348 | MED 5.0 | cisco wide_area_application_services Cisco Wide Area Application Services (WAAS) appliances with software 4.4, 5.0, and 5.1 include a one-way hash of a password within output text, which might allow remote attackers to obtain sensitive information via a brute-force attack on the hash string, aka | 1.2% | — |
| CVE-2021-35940 | HIGH 7.1 | apache portable_runtime An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 an | 1.2% | — |
| CVE-2020-5906 | HIGH 8.1 | f5 big-ip_access_policy_manager In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files. This allows Admin and Resource Admin users with Secure Copy (SCP) protocol access to read and overwr | 1.2% | — |
| CVE-2018-20764 | CRIT 9.8 | helpsystems boks A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege escalation. | 1.2% | — |
| CVE-2018-8415 | HIGH 7.8 | microsoft powershell_core A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerability." This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, | 1.2% | — |
| CVE-2018-0254 | MED 5.3 | cisco secure_firewall_threat_defense A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. | 1.2% | — |
| CVE-2018-0244 | MED 5.8 | cisco secure_firewall_threat_defense A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy to drop the Server Message Block (SMB) protocol if a malware file is detected. The vulnerabilit | 1.2% | — |
| CVE-2018-0243 | MED 5.8 | cisco secure_firewall_threat_defense A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy that is intended to drop the Server Message Block Version 2 (SMB2) and SMB Version 3 (SMB3) pro | 1.2% | — |
| CVE-2014-8015 | MED 4.0 | cisco identity_services_engine_software The Sponsor Portal in Cisco Identity Services Engine (ISE) allows remote authenticated users to obtain access to an arbitrary sponsor's guest account via a modified HTTP request, aka Bug ID CSCur64400. | 1.2% | — |
| CVE-2013-1108 | MED 4.0 | cisco webex_training_center Cisco WebEx Training Center allows remote authenticated users to remove hands-on lab-session reservations via a crafted URL, aka Bug ID CSCzu81064. | 1.2% | — |
| CVE-2023-24897 | HIGH 7.8 | microsoft .net .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2021-1489 | MED 6.5 | cisco firepower_device_manager A vulnerability in filesystem usage management for Cisco Firepower Device Manager (FDM) Software could allow an authenticated, remote attacker to exhaust filesystem resources, resulting in a denial of service (DoS) condition on an affected device. This vulnera | 1.2% | — |
| CVE-2018-8549 | MED 5.5 | microsoft windows_10 A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 201 | 1.2% | — |
| CVE-2016-9209 | MED 4.3 | cisco firepower_services_for_adaptive_security_appliance A vulnerability in TCP processing in Cisco FirePOWER system software could allow an unauthenticated, remote attacker to download files that would normally be blocked. Affected Products: The following Cisco products are vulnerable: Adaptive Security Appliance ( | 1.2% | — |
| CVE-2015-3626 | MED 4.3 | fortinet fortios Cross-site scripting (XSS) vulnerability in the DHCP Monitor page in the Web User Interface (WebUI) in Fortinet FortiOS before 5.2.4 on FortiGate devices allows remote attackers to inject arbitrary web script or HTML via a crafted hostname. | 1.2% | — |
| CVE-2011-0695 | MED 5.7 | canonical ubuntu_linux Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request while other request handlers are still r | 1.2% | — |
| CVE-2025-24061 | HIGH 7.8 | microsoft windows_10_1507 Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally. | 1.2% | — |
| CVE-2024-20692 | MED 5.7 | microsoft windows_10_1507 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | 1.2% | — |
| CVE-2023-20162 | HIGH 8.6 | cisco business_250-16p-2g_firmware Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected | 1.2% | — |
| CVE-2023-20158 | HIGH 8.6 | cisco business_250-16p-2g_firmware Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected | 1.2% | — |