58.535 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.535 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-10851 | HIGH 7.8 | fujixerox contentsbridge_utility Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 1.1% | — |
| CVE-2026-33858 | HIGH 8.8 | apache airflow Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended | 1.1% | — |
| CVE-2026-27651 | HIGH 7.5 | f5 nginx_open_source When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server p | 1.1% | — |
| CVE-2024-43610 | HIGH 7.4 | microsoft copilot_studio Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector | 1.1% | — |
| CVE-2024-31869 | MED 4.3 | apache airflow Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via the "configuration" UI page when "non-sensitive-only" was set as "webserver.expose_config" configuration (The celery provide | 1.1% | — |
| CVE-2023-24895 | HIGH 7.8 | microsoft .net .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2019-6610 | HIGH 8.6 | f5 big-ip_access_policy_manager On BIG-IP versions 14.0.0-14.0.0.4, 13.0.0-13.1.1.1, 12.1.0-12.1.4, 11.6.0-11.6.3.4, and 11.5.1-11.5.8, the system is vulnerable to a denial of service attack when performing URL classification. | 1.1% | — |
| CVE-2018-16968 | LOW 3.1 | citrix sharefile_storagezones_controller Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal. | 1.1% | — |
| CVE-2005-3257 | MED 4.6 | linux linux_kernel The VT implementation (vt_ioctl.c) in Linux kernel 2.6.12, and possibly other versions including 2.6.14.4, allows local users to use the KDSKBSENT ioctl on terminals of other users and gain privileges, as demonstrated by modifying key bindings using loadkeys. | 1.1% | — |
| CVE-2023-21800 | HIGH 7.8 | microsoft windows_server_2008 Windows Installer Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2022-22203 | MED 6.5 | juniper junos An Incorrect Comparison vulnerability in PFE of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS). On QFX5000 Series, and EX4600 and EX4650 platforms, the fxpc process will crash followed by the FPC reboot | 1.1% | — |
| CVE-2021-1725 | MED 5.5 | microsoft bot_framework_software_development_kit Bot Framework SDK Information Disclosure Vulnerability | 1.1% | — |
| CVE-2020-3449 | MED 4.3 | cisco ios_xr A vulnerability in the Border Gateway Protocol (BGP) additional paths feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent authorized users from monitoring the BGP status and cause the BGP process to stop processing new u | 1.1% | — |
| CVE-2020-0983 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Delivery Optimization service improperly handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-1009, CVE-2020-1011, CVE- | 1.1% | — |
| CVE-2019-1931 | MED 6.1 | cisco secure_firewall_management_center Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based manage | 1.1% | — |
| CVE-2019-1930 | MED 6.1 | cisco secure_firewall_management_center Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based manage | 1.1% | — |
| CVE-2019-1852 | MED 6.1 | cisco network_registrar A vulnerability in the web-based management interface of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insuffi | 1.1% | — |
| CVE-2019-15259 | MED 6.1 | cisco unified_contact_center_express A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed t | 1.1% | — |
| CVE-2019-12716 | MED 6.1 | cisco unified_communications_manager A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against | 1.1% | — |
| CVE-2019-12715 | MED 6.1 | cisco unified_communications_manager A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against | 1.1% | — |
| CVE-2019-12713 | MED 6.1 | cisco prime_infrastructure A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. Th | 1.1% | — |
| CVE-2019-12712 | MED 6.1 | cisco prime_infrastructure A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. Th | 1.1% | — |
| CVE-2019-12707 | MED 6.1 | cisco unified_communications_manager A vulnerability in the web-based interface of multiple Cisco Unified Communications products could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The | 1.1% | — |
| CVE-2019-12695 | MED 6.1 | cisco adaptive_security_appliance A vulnerability in the Clientless SSL VPN (WebVPN) portal of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user | 1.1% | — |
| CVE-2019-12631 | MED 6.1 | cisco identity_services_engine A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due | 1.1% | — |