58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-21172 | HIGH 8.1 | debian debian_linux Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | 1.7% | — |
| CVE-2021-1683 | MED 5.0 | microsoft windows_10 Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software | 1.7% | — |
| CVE-2016-1398 | MED 6.5 | cisco rv110w_firmware Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware through 1.2.1.4, RV130W devices with firmware through 1.0.2.7, and RV215W devices with firmware through 1.3.0.7 allows remote authenticated users to cause a denial of s | 1.7% | — |
| CVE-2023-33140 | MED 6.5 | microsoft onenote Microsoft OneNote Spoofing Vulnerability | 1.6% | — |
| CVE-2021-3058 | HIGH 8.8 | paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 vers | 1.6% | — |
| CVE-2020-0903 | MED 5.4 | microsoft exchange_server A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'. | 1.6% | — |
| CVE-2019-0685 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0803, CVE-2019-0859. | 1.6% | — |
| CVE-2017-12287 | MED 4.3 | cisco expressway A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process on an affected system | 1.6% | — |
| CVE-2016-1368 | HIGH 7.5 | cisco firesight_system_software Cisco FirePOWER System Software 5.3.x through 5.3.0.6 and 5.4.x through 5.4.0.3 on FirePOWER 7000 and 8000 appliances, and on the Advanced Malware Protection (AMP) for Networks component on these appliances, allows remote attackers to cause a denial of service | 1.6% | — |
| CVE-2023-36801 | MED 5.3 | microsoft windows_server_2008 DHCP Server Service Information Disclosure Vulnerability | 1.6% | — |
| CVE-2016-5092 | MED 4.9 | fortinet fortiweb Directory traversal vulnerability in Fortinet FortiWeb before 5.5.3 allows remote authenticated administrators with read and write privileges to read arbitrary files by leveraging the autolearn feature. | 1.6% | — |
| CVE-2016-2782 | MED 4.6 | linux linux_kernel The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB de | 1.6% | — |
| CVE-2015-4320 | MED 4.0 | cisco telepresence_video_communication_server_software The Configuration Log File component in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to obtain sensitive information by reading a log file, aka Bug ID CSCuv12340. | 1.6% | — |
| CVE-2013-2940 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2939 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2938 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2937 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2936 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2935 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2934 | HIGH 10.0 | citrix cloudportal_services_manager Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 does not properly restrict access to web services, which has unspecified impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2933 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2026-35416 | HIGH 7.0 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 1.6% | — |
| CVE-2023-46851 | MED 4.9 | apache allura Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrators can run these imports, which could cause Allura to read local files and expose them. Exposing internal files then can lead to other expl | 1.6% | — |
| CVE-2020-17048 | MED 4.2 | microsoft chakracore Chakra Scripting Engine Memory Corruption Vulnerability | 1.6% | — |
| CVE-2019-1963 | HIGH 7.7 | cisco fx-os A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application on an affected device to restart unexpectedly. T | 1.6% | — |