58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-21303 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2022-26850 | MED 4.3 | apache nifi When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers configuration to the operating system temporary directory. On most platforms, the operating system temporary directory has global read permis | 1.5% | — |
| CVE-2021-1373 | HIGH 8.6 | cisco ios_xe A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause | 1.5% | — |
| CVE-2019-1970 | MED 5.8 | cisco secure_firewall_management_center A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected s | 1.5% | — |
| CVE-2019-1909 | MED 6.8 | cisco ios_xr A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to incorr | 1.5% | — |
| CVE-2019-12701 | MED 5.8 | cisco secure_firewall_management_center A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass the file and malware inspection policies on an affected system. The vulnerability exists be | 1.5% | — |
| CVE-2017-5052 | HIGH 8.8 | google chrome An incorrect assumption about block structure in Blink in Google Chrome prior to 57.0.2987.133 for Mac, Windows, and Linux, and 57.0.2987.132 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page that triggers | 1.5% | — |
| CVE-2016-1290 | HIGH 8.1 | cisco evolved_programmable_network_manager The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a | 1.5% | — |
| CVE-1999-0794 | MED 4.6 | microsoft excel Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file. | 1.5% | — |
| CVE-2023-36427 | HIGH 7.0 | microsoft windows_10_1809 Windows Hyper-V Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2019-1953 | MED 6.5 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging the admin password when a user is forced t | 1.5% | — |
| CVE-2017-5583 | MED 6.5 | paloaltonetworks pan-os The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to read arbitrary files via unspecified vectors. | 1.5% | — |
| CVE-2016-3305 | HIGH 7.8 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 mishandles session objects, which allows local users to hijack sessi | 1.5% | — |
| CVE-2016-1380 | HIGH 7.5 | cisco web_security_appliance Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (proxy-process hang) via a crafted HTTP POST request, aka Bug ID CSCuo12171. | 1.5% | — |
| CVE-2023-25613 | CRIT 9.8 | apache kerby_ldap_backend An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3. | 1.5% | — |
| CVE-2018-0474 | HIGH 8.8 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view digest credentials in clear text. The vulnerability is due to the incorrect inclusion of saved passwords in conf | 1.5% | — |
| CVE-2013-6939 | MED 5.0 | citrix netscaler_application_delivery_controller_firmware Unspecified vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows attackers to cause a denial of service via unknown vectors, related to "RADIUS authentication." | 1.5% | — |
| CVE-2020-3142 | HIGH 7.5 | cisco webex_meetings_online A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a password-protected meeting without providing the meeting password. The connection attempt must initiate from a W | 1.5% | — |
| CVE-2020-0821 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1007. | 1.5% | — |
| CVE-2017-3844 | MED 4.3 | cisco prime_collaboration_assurance A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file directory listings and download files. Affected Products: Cisco Prime Collaboration Assurance softwa | 1.5% | — |
| CVE-2017-3843 | MED 4.3 | cisco prime_collaboration_assurance A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files that should be restricted. More Information: CSCvc99446. Known Affected Releases: 11.5(0). | 1.5% | — |
| CVE-2016-8455 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. | 1.5% | — |
| CVE-2015-8964 | MED 5.5 | linux linux_kernel The tty_set_termios_ldisc function in drivers/tty/tty_ldisc.c in the Linux kernel before 4.5 allows local users to obtain sensitive information from kernel memory by reading a tty data structure. | 1.5% | — |
| CVE-1999-1322 | MED 4.6 | broadcom arcserve_backup The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext. | 1.5% | — |
| CVE-2025-21248 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.5% | — |