IT
58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.639 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2023-20127 MED 6.5 cisco prime_infrastructure Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-s 0.9% —
CVE-2022-44691 HIGH 7.8 microsoft 365_apps Microsoft Office OneNote Remote Code Execution Vulnerability 0.9% —
CVE-2022-38011 HIGH 7.3 microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability 0.9% —
CVE-2020-16887 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>To exploit the vu 0.9% —
CVE-2020-0647 MED 5.4 microsoft office_online_server A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. 0.9% —
CVE-2017-10623 HIGH 7.1 juniper junos_space Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to intercept, inject or disrupt Junos Space cluster operations between two nodes. Affected releases are Juniper Networks 0.9% —
CVE-2025-54107 MED 4.3 microsoft windows_10_1507 Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. 0.9% —
CVE-2024-26201 MED 6.6 microsoft intune_company_portal Microsoft Intune Linux Agent Elevation of Privilege Vulnerability 0.9% —
CVE-2023-20243 HIGH 8.6 cisco identity_services_engine A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling o 0.9% —
CVE-2022-20844 MED 5.3 cisco sd-wan A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC using a default static username and password co 0.9% —
CVE-2021-23038 CRIT 9.0 f5 big-ip_access_policy_manager On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allo 0.9% —
CVE-2021-20443 HIGH 8.8 ibm maximo_for_civil_infrastructure IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is outside of the intended control sphere. IBM X-Force ID: 196619. 0.9% —
CVE-2020-9345 MED 6.5 signotec signopad-api\/web An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the application doesn't limit the number of opened WebSocket sockets. If a victim visits 0.9% —
CVE-2020-1997 MED 5.3 paloaltonetworks pan-os An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection target away from the trusted GlobalProtect gateway. If the user then successfully authenticates it will cause t 0.9% —
CVE-2016-3710 HIGH 8.8 canonical ubuntu_linux The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue. 0.9% —
CVE-2016-2887 HIGH 8.1 ibm ims_enterprise_suite IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors. 0.9% —
CVE-2016-1321 MED 5.8 cisco universal_small_cell_firmware Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to bypass a certain certificate-validation feature and obtain sensitive firmware-image and IP address data via a 0.9% —
CVE-2015-0580 MED 6.5 cisco secure_access_control_system Multiple SQL injection vulnerabilities in the ACS View reporting interface pages in Cisco Secure Access Control System (ACS) before 5.5 patch 7 allow remote authenticated administrators to execute arbitrary SQL commands via crafted HTTPS requests, aka Bug ID C 0.9% —
CVE-2025-21379 HIGH 7.1 microsoft windows_11_24h2 DHCP Client Service Remote Code Execution Vulnerability 0.9% —
CVE-2024-35823 MED 5.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: vt: fix unicode buffer corruption when deleting characters This is the same issue that was fixed for the VGA text buffer in commit 39cdb68c64d8 ("vt: fix memory overlapping when deleting cha 0.9% —
CVE-2023-21734 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 0.9% —
CVE-2023-20214 CRIT 9.1 cisco catalyst_sd-wan_manager A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vM 0.9% —
CVE-2022-48747 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: block: Fix wrong offset in bio_truncate() bio_truncate() clears the buffer outside of last block of bdev, however current bio_truncate() is using the wrong offset of page. So it can return t 0.9% —
CVE-2022-29480 MED 5.3 f5 big-ip_access_policy_manager On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests to big3d can cause an increase in CPU resource utilization. Note: Software versions which have reached End of 0.9% —
CVE-2022-29479 MED 5.3 f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized Management all versions of 8.x and 7.x, when an IPv6 self IP address is configu 0.9% —