58.532 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.532 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1131 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit | 1.1% | — |
| CVE-2019-1878 | HIGH 7.5 | cisco telepresence_ce A vulnerability in the Cisco Discovery Protocol (CDP) implementation for the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, adjacent attacker to inject arbitrary shell commands that are executed by the de | 1.1% | — |
| CVE-2017-2339 | HIGH 8.4 | juniper screenos A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including | 1.1% | — |
| CVE-2017-2338 | HIGH 8.4 | juniper screenos A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including | 1.1% | — |
| CVE-2017-2337 | HIGH 8.4 | juniper screenos A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including | 1.1% | — |
| CVE-2017-2335 | HIGH 8.4 | juniper screenos A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including | 1.1% | — |
| CVE-2015-0626 | MED 4.3 | cisco hosted_collaboration_solution The SOAP interface in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to obtain access to system-management tools via crafted Challenge SOAP calls, aka Bug ID CSCuc38114. | 1.1% | — |
| CVE-2014-1957 | MED 6.5 | fortinet fortiweb FortiGuard FortiWeb before 5.0.3 allows remote authenticated users to gain privileges via unspecified vectors. | 1.1% | — |
| CVE-2013-4604 | MED 6.5 | fortinet fortios Fortinet FortiOS before 5.0.3 on FortiGate devices does not properly restrict Guest capabilities, which allows remote authenticated users to read, modify, or delete the records of arbitrary users by leveraging the Guest role. | 1.1% | — |
| CVE-2023-1194 | HIGH 7.1 | fedoraproject fedora An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check o | 1.1% | — |
| CVE-2021-36195 | MED 4.2 | fortinet fortiweb Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 may allow an authenticated attacker to execute arbitrary commands on the underlying | 1.1% | — |
| CVE-2021-26092 | MED 4.7 | fortinet fortios Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.12, 6.2.0 through 6.2.7, 6.4.0 through 6.4.4; and FortiProxy 1.2.0 through 1.2.9, 2.0.0 through 2.0.1 may allow | 1.1% | — |
| CVE-2018-0303 | HIGH 8.8 | cisco firepower_extensible_operating_system A vulnerability in the Cisco Discovery Protocol component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on the affected device. T | 1.1% | — |
| CVE-2022-30214 | MED 6.6 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2020-3242 | MED 4.9 | cisco ucs_director A vulnerability in the REST API of Cisco UCS Director could allow an authenticated, remote attacker with administrative privileges to obtain confidential information from an affected device. The vulnerability exists because confidential information is returned | 1.1% | — |
| CVE-2020-1571 | HIGH 7.3 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Setup in the way it handles permissions. A locally authenticated attacker could run arbitrary code with elevated system privileges. After successfully exploiting the vulnerability, an attacker could the | 1.1% | — |
| CVE-2017-7739 | MED 6.1 | fortinet fortios A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script or HTML in the context of the victim's | 1.1% | — |
| CVE-2013-7313 | MED 5.4 | juniper junos The OSPF implementation in Juniper Junos through 13.x, JunosE, and ScreenOS through 6.3.x does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allo | 1.1% | — |
| CVE-2011-4731 | MED 5.0 | parallels parallels_plesk_panel The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 includes an RFC 1918 IP address within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by admin/home/ | 1.1% | — |
| CVE-2011-2042 | MED 5.0 | cisco ciscoworks_common_services The Sybase SQL Anywhere database component in Cisco CiscoWorks Common Services 3.x and 4.x before 4.1 allows remote attackers to obtain potentially sensitive information about the engine name and database port via an unspecified request to UDP port 2638, aka B | 1.1% | — |
| CVE-2010-1568 | MED 5.0 | cisco ironport_desktop_flag_plugin_for_outlook The Send Secure functionality in the Cisco IronPort Desktop Flag Plug-in for Outlook before 6.5.0-006 does not properly handle simultaneously composed messages, which might allow remote attackers to obtain cleartext contents of e-mail messages that were intend | 1.1% | — |
| CVE-2010-0141 | MED 6.4 | cisco unified_meetingplace MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote attackers to discover usernames, passwords, and unspecified other data from the user database via a modified authentication sequence to the Audio Server, aka Bug ID CSCsv7693 | 1.1% | — |
| CVE-2025-32722 | MED 5.5 | microsoft windows_10_1507 Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally. | 1.1% | — |
| CVE-2021-41784 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled. | 1.1% | — |
| CVE-2021-22997 | HIGH 7.5 | f5 big-iq_centralized_management On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service does not implement any form of authentication for the clustering transport services, and all data used by ElasticSearch for transport is unencrypted. Note: Software versions which ha | 1.1% | — |