58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-5045 | MED 6.1 | debian debian_linux XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed detection of a blocked iframe load, which allowed a remote attacker to brute force JavaScript variables via a crafted HTML page. | 1.2% | — |
| CVE-2017-3868 | MED 6.1 | cisco unified_computing_system_director A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Informat | 1.2% | — |
| CVE-2017-3866 | MED 6.1 | cisco prime_service_catalog A vulnerability in the web framework code of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc79842 C | 1.2% | — |
| CVE-2017-3848 | MED 6.1 | cisco prime_infrastructure A vulnerability in the HTTP web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected system. More Information | 1.2% | — |
| CVE-2017-3802 | MED 6.1 | cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvc20679. Known Affected Relea | 1.2% | — |
| CVE-2014-2713 | MED 5.0 | juniper junos Juniper Junos before 11.4R11, 12.1 before 12.1R9, 12.2 before 12.2R7, 12.3R4 before 12.3R4-S3, 13.1 before 13.1R4, 13.2 before 13.2R2, and 13.3 before 13.3R1, as used in MX Series and T4000 routers, allows remote attackers to cause a denial of service (PFE res | 1.2% | — |
| CVE-2010-0485 | HIGH 7.8 | microsoft windows_2000 The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new windo | 1.2% | — |
| CVE-2024-43488 | HIGH 8.8 | microsoft visual_studio_code Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector. | 1.2% | — |
| CVE-2022-21895 | HIGH 7.8 | microsoft windows_10 Windows User Profile Service Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2021-43242 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.2% | — |
| CVE-2019-5512 | HIGH 8.8 | vmware workstation VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately. Successful exploitation of this issue may allow hijacking of COM classes used by the VMX process, on a Windows host, leading to elevation | 1.2% | — |
| CVE-2016-8966 | MED 5.9 | ibm bigfix_inventory IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle | 1.2% | — |
| CVE-2016-8434 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comprom | 1.2% | — |
| CVE-2016-7458 | MED 5.8 | vmware vsphere_client VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External En | 1.2% | — |
| CVE-2010-3416 | CRIT 9.8 | google chrome Google Chrome before 6.0.472.59 on Linux does not properly implement the Khmer locale, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. | 1.2% | — |
| CVE-2004-1163 | MED 5.0 | cisco cns_network_registrar Cisco CNS Network Registrar Central Configuration Management (CCM) server 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (CPU consumption) by ending a connection after sending a certain sequence of packets. | 1.2% | — |
| CVE-2023-43667 | HIGH 7.5 | apache inlong Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false log records, making it har | 1.2% | — |
| CVE-2022-35753 | HIGH 8.1 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-35752 | HIGH 8.1 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-35745 | HIGH 8.1 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-20758 | MED 6.8 | cisco ios_xr A vulnerability in the implementation of the Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the | 1.2% | — |
| CVE-2021-38642 | MED 6.1 | microsoft edge Microsoft Edge for iOS Spoofing Vulnerability | 1.2% | — |
| CVE-2021-38641 | MED 6.1 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 1.2% | — |
| CVE-2019-1942 | MED 4.3 | cisco identity_services_engine A vulnerability in the sponsor portal web interface for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficien | 1.2% | — |
| CVE-2019-0028 | HIGH 7.5 | juniper junos On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a BGP session restart on a remote peer that has the graceful restart mechanism enabled may cause the local routing protocol daemon (RPD) process t | 1.2% | — |