58.535 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.535 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-6958 | MED 6.1 | vmware vrealize_automation VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to the compromise of the vRA user's workstation. | 1.0% | — |
| CVE-2017-4929 | MED 6.1 | vmware nsx_edge VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a moderate Cross-Site Scripting (XSS) issue which may lead to information disclosure. | 1.0% | — |
| CVE-2014-0738 | MED 4.3 | cisco adaptive_security_appliance_software The Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL) file, aka Bug ID CSCuj66770. | 1.0% | — |
| CVE-2011-4853 | MED 4.3 | parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes an RFC 1918 IP address within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by smb/user/list-data/items-pe | 1.0% | — |
| CVE-2011-4852 | MED 4.3 | parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates web pages containing external links in response to GET requests with query strings for enterprise/mobile-monitor/ and certain other files, which makes it easier for remote attackers t | 1.0% | — |
| CVE-2009-5086 | MED 4.3 | juniper idp Cross-site scripting (XSS) vulnerability in Appliance Configuration Manager (ACM) in Juniper IDP 4.1 before 4.1r3 and 4.2 before 4.2r1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 1.0% | — |
| CVE-2008-4405 | HIGH 7.2 | citrix xen xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecifi | 1.0% | — |
| CVE-2026-8505 | CRIT 9.8 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuratio | 1.0% | — |
| CVE-2025-27818 | HIGH 8.8 | apache kafka A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and | 1.0% | — |
| CVE-2022-20752 | MED 5.3 | cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This | 1.0% | — |
| CVE-2021-42307 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 1.0% | — |
| CVE-2016-9256 | HIGH 7.5 | f5 big-ip_access_policy_manager In F5 BIG-IP 12.1.0 through 12.1.2, permissions enforced by iControl can lag behind the actual permissions assigned to a user if the role_map is not reloaded between the time the permissions are changed and the time of the user's next request. This is a race c | 1.0% | — |
| CVE-2015-4215 | MED 6.1 | cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) devices with software 7.5(102.0) and 7.6(1.62) allow remote attackers to cause a denial of service (device crash) by triggering an exception during attempted forwarding of unspecified IPv6 packets to a non-IPv6 device, aka B | 1.0% | — |
| CVE-2006-4814 | MED 4.6 | linux linux_kernel The mincore function in the Linux kernel before 2.4.33.6 does not properly lock access to user space, which has unspecified impact and attack vectors, possibly related to a deadlock. | 1.0% | — |
| CVE-2025-27556 | MED 5.8 | djangoproject django An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are subject to | 1.0% | — |
| CVE-2025-21216 | MED 6.5 | microsoft windows_10_1607 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.0% | — |
| CVE-2025-21212 | MED 6.5 | microsoft windows_10_1607 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.0% | — |
| CVE-2022-33635 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-22982 | HIGH 7.5 | vmware cloud_foundation The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service. | 1.0% | — |
| CVE-2020-4945 | HIGH 8.1 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945. | 1.0% | — |
| CVE-2020-3333 | MED 5.3 | cisco application_policy_infrastructure_controller A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update event policies on an affected device. The vulnerability is due to insufficient authentication of users who modify policies on an | 1.0% | — |
| CVE-2018-1000117 | MED 6.7 | python python Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be explo | 1.0% | — |
| CVE-2013-5517 | MED 5.5 | cisco unified_communications_domain_manager SQL injection vulnerability in the web framework in Cisco Unified Communications Domain Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuh96567. | 1.0% | — |
| CVE-2010-4077 | LOW 1.9 | linux linux_kernel The ntty_ioctl_tiocgicount function in drivers/char/nozomi.c in the Linux kernel 2.6.36.1 and earlier does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a T | 1.0% | — |
| CVE-2024-48019 | MED 5.4 | apache doris Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris. Application administrators can read arbitrary files from the server filesystem through path tra | 1.0% | — |