IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2023-26281 MED 5.9 ibm http_server IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL. IBM X-Force ID: 248296. 1.1% —
CVE-2022-22197 HIGH 7.5 juniper junos An Operation on a Resource after Expiration or Release vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker with an established BGP session to cause a Denial of Se 1.1% —
CVE-2021-3046 MED 6.8 paloaltonetworks pan-os An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentica 1.1% —
CVE-2018-8641 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows 1.1% —
CVE-2018-15429 MED 5.3 cisco hyperflex_hx_data_platform A vulnerability in the web-based UI of Cisco HyperFlex HX Data Platform Software could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to a lack of proper input and authorization of HTTP 1.1% —
CVE-2024-6912 CRIT 9.8 perkinelmer processplus Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0. 1.1% —
CVE-2021-1530 MED 5.4 cisco broadworks_messaging_server A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could allow an authenticated, remote attacker to access sensitive information or cause a partial denial of service (DoS) condition on an affected system. This v 1.1% —
CVE-2024-49115 HIGH 8.1 microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.1% —
CVE-2024-38187 HIGH 7.8 microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 1.1% —
CVE-2024-38185 HIGH 7.8 microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 1.1% —
CVE-2023-35308 MED 6.5 microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability 1.1% —
CVE-2022-35845 HIGH 7.8 fortinet fortitester Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.0 all versions, 4.0.0 through 4.2.0, 2.3.0 through 3.9.1 may allow an authenticated attacker to execute arbitra 1.1% —
CVE-2020-17071 MED 5.5 microsoft windows_10 Windows Delivery Optimization Information Disclosure Vulnerability 1.1% —
CVE-2020-17069 MED 5.5 microsoft windows_10 Windows NDIS Information Disclosure Vulnerability 1.1% —
CVE-2016-1357 MED 5.3 cisco cisco_policy_suite The password-management administration component in Cisco Policy Suite (CPS) 7.0.1.3, 7.0.2, 7.0.2-att, 7.0.3-att, 7.0.4-att, and 7.5.0 allows remote attackers to bypass intended RBAC restrictions and read unspecified data via unknown vectors, aka Bug ID CSCut 1.1% —
CVE-2011-4019 MED 5.4 cisco ios Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM) 7.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted response to a SIP SUBSCRIBE message, aka Bug IDs CSCto93837 and CS 1.1% —
CVE-2023-36388 MED 4.3 apache superset Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possible SSRF. 1.1% —
CVE-2023-30576 MED 6.8 apache guacamole Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allow an attacker to execute arbitrary code with the privileges of the guacd process. 1.1% —
CVE-2023-21705 HIGH 8.8 microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability 1.1% —
CVE-2022-22485 CRIT 9.8 ibm spectrum_protect_operations_center In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this 1.1% —
CVE-2021-0261 HIGH 7.5 juniper junos A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Captive Portal allows an unauthenticated attacker to cause an extended Denial of Service (DoS) for thes 1.1% —
CVE-2018-0902 HIGH 7.8 microsoft windows_10 The Cryptography Next Generation (CNG) kernel-mode driver (cng.sys) in Windows 10 Gold, 1511, 1607, 1703, and 1709. Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to the way the kernel-mode driver valida 1.1% —
CVE-2018-0884 HIGH 7.8 microsoft windows_10 Windows Scripting Host (WSH) in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to how objects are handled in memory, aka "Windows Security Feature Bypass Vulne 1.1% —
CVE-2011-3293 MED 6.8 cisco secure_access_control_server Multiple cross-site request forgery (CSRF) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequence 1.1% —
CVE-2023-36710 HIGH 7.8 microsoft windows_10_1507 Windows Media Foundation Core Remote Code Execution Vulnerability 1.1% —