58.535 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.535 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1649 | HIGH 7.5 | juniper junos When a device running Juniper Networks Junos OS with MPC7, MPC8, or MPC9 line cards installed and the system is configured for inline IP reassembly, used by L2TP, MAP-E, GRE, and IPIP, the packet forwarding engine (PFE) will become disabled upon receipt of sma | 1.1% | — |
| CVE-2020-1601 | MED 5.3 | juniper junos Certain types of malformed Path Computation Element Protocol (PCEP) packets when received and processed by a Juniper Networks Junos OS device serving as a Path Computation Client (PCC) in a PCEP environment using Juniper's path computational element protocol d | 1.1% | — |
| CVE-2019-12711 | MED 6.5 | cisco unified_communications_manager A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of se | 1.1% | — |
| CVE-2018-8399 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018- | 1.1% | — |
| CVE-2018-8339 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior, aka "Windows Installer Elevation of Privilege Vulnerability." This affects Wind | 1.1% | — |
| CVE-2017-2333 | MED 6.5 | juniper northstar_controller A persistent denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network-based, authenticated attacker to consume enough system resources to cause a persistent denial | 1.1% | — |
| CVE-2017-0330 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the NVIDIA crypto driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product | 1.1% | — |
| CVE-2015-6363 | LOW 3.5 | cisco firesight_system_software Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco FireSIGHT Management Center (MC) 5.4.1.4 and 6.0.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuw88396. | 1.1% | — |
| CVE-2015-0706 | MED 5.8 | cisco firesight_system_software Open redirect vulnerability in Cisco FireSIGHT System Software 5.3.1.1, 5.3.1.2, and 6.0.0 in FireSIGHT Management Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted HTTP header, aka Bug IDs CSCut | 1.1% | — |
| CVE-2014-2882 | HIGH 10.0 | citrix netscaler_access_gateway Unspecified vulnerability in the management GUI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unspecified impact and vectors, related to certificate validation. | 1.1% | — |
| CVE-2025-32710 | HIGH 8.1 | microsoft windows_server_2008 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.1% | — |
| CVE-2022-27510 | CRIT 9.8 | citrix application_delivery_controller_firmware Unauthorized access to Gateway user capabilities | 1.1% | — |
| CVE-2021-35240 | MED 6.5 | solarwinds orion_platform A security researcher stored XSS via a Help Server setting. This affects customers using Internet Explorer, because they do not support 'rel=noopener'. | 1.1% | — |
| CVE-2020-3546 | MED 5.3 | cisco asyncos A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to insuffic | 1.1% | — |
| CVE-2017-8040 | MED 6.5 | vmware single_sign-on_for_pivotal_cloud_foundry In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attack was discovered in the Single Sign-On service dashboard. Privileged users can in some cases upload malformed X | 1.1% | — |
| CVE-2013-5096 | MED 4.0 | juniper junos_space Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly implement role-based access control, which allows remote authenticated users to modify the configuration by leveraging the read-only privilege, aka PR | 1.1% | — |
| CVE-2026-57967 | CRIT 9.8 | apache artemis An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache Act | 1.1% | — |
| CVE-2025-31104 | HIGH 7.2 | fortinet fortiadc A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiADC 7.6.0 through 7.6.1, FortiADC 7.4.0 through 7.4.6, FortiADC 7.2.0 through 7.2.7, FortiADC 7.1.0 through 7.1.4, FortiADC 7.0 all vers | 1.1% | — |
| CVE-2024-23349 | MED 5.4 | apache answer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. XSS attack when user enters summary. A logged-in user, when modifying their own submitted ques | 1.1% | — |
| CVE-2023-24487 | MED 6.3 | citrix application_delivery_controller Arbitrary file read in Citrix ADC and Citrix Gateway | 1.1% | — |
| CVE-2023-20220 | HIGH 7.2 | cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. To exploit these vulnerabilities, | 1.1% | — |
| CVE-2022-29968 | HIGH 7.8 | fedoraproject fedora An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private. | 1.1% | — |
| CVE-2022-26071 | HIGH 7.4 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a flaw in the way reply ICMP packets are limited in the Traffic Manage | 1.1% | — |
| CVE-2021-36180 | HIGH 8.1 | fortinet fortiweb Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.5 and below may allow an authenticated attacker to execute unauthorized code or commands via | 1.1% | — |
| CVE-2021-3055 | MED 6.5 | paloaltonetworks pan-os An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the fi | 1.1% | — |