IT
58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.414 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2020-3926 MED 6.1 changingtec servisign An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter. 1.5% —
CVE-2019-9548 CRIT 10.0 citrix application_delivery_management Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control. 1.5% —
CVE-2019-1486 MED 6.1 microsoft visual_studio_2019 A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'. 1.5% —
CVE-2019-12292 CRIT 9.8 citrix appdna Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control. 1.5% —
CVE-2018-0854 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Windows Scripting Host which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is 1.5% —
CVE-2018-0397 MED 5.9 cisco advanced_malware_protection_for_endpoints A vulnerability in Cisco AMP for Endpoints Mac Connector Software installed on Apple macOS 10.12 could allow an unauthenticated, remote attacker to cause a kernel panic on an affected system, resulting in a denial of service (DoS) condition. The vulnerability 1.5% —
CVE-2013-1223 HIGH 7.8 cisco unified_customer_voice_portal The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly validate an unspecified parameter, which allows remote attackers to read arbitrary files via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub3837 1.5% —
CVE-2010-3033 HIGH 9.0 cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different v 1.5% —
CVE-2010-2843 HIGH 9.0 cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different v 1.5% —
CVE-2010-2842 HIGH 9.0 cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different v 1.5% —
CVE-2006-6572 MED 6.5 citrix access_gateway Unspecified vulnerability in Citrix Advanced Access Control (AAC) Option 4.0, and Access Gateway 4.2 with Advanced Access Control 4.2, before 20061114, when the Browser-Only access feature is enabled, allows remote authenticated users to bypass access policies 1.5% —
CVE-2021-40727 HIGH 7.8 adobe indesign Access of Memory Location After End of Buffer (CWE-788 1.5% —
CVE-2020-4879 CRIT 9.8 ibm cognos_controller IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847. 1.5% —
CVE-2018-4437 HIGH 8.8 apple icloud Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9. 1.5% —
CVE-1999-0628 MED 5.0 freebsd freebsd The rwho/rwhod service is running, which exposes machine status and user information. 1.5% —
CVE-2026-21260 HIGH 7.5 microsoft 365_apps Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. 1.5% —
CVE-2022-20714 HIGH 8.6 cisco ios_xr A vulnerability in the data plane microcode of Lightspeed-Plus line cards for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the line card to reset. This vulnerability is due to the incorrect handlin 1.5% —
CVE-2021-27193 CRIT 9.8 netop vision_pro Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation. 1.5% —
CVE-2019-1640 HIGH 7.8 cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im 1.5% —
CVE-2019-1639 HIGH 7.8 cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im 1.5% —
CVE-2019-1638 HIGH 7.8 cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im 1.5% —
CVE-2019-1637 HIGH 7.8 cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im 1.5% —
CVE-2011-0244 MED 4.3 apple safari WebKit in Apple Safari before 5.0.6 allows user-assisted remote attackers to read arbitrary files via vectors related to improper canonicalization of URLs within RSS feeds. 1.5% —
CVE-2010-4165 MED 4.9 linux linux_kernel The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MAXSEG (aka MSS) values, which allows local users to cause a denial of service (OOPS) via a setsockopt call that specifies a small value, lead 1.5% —
CVE-2026-21520 HIGH 7.5 microsoft copilot_studio Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector 1.5% —