57.551 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-13914 | HIGH 8.7 | juniper apstra A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an attacker can perform a mac | 0.3% | — |
| CVE-2024-49035 | HIGH 8.7 | microsoft partner_center An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. | 1.3% | |
| CVE-2024-43591 | HIGH 8.7 | microsoft azure_command-line_interface Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability | 1.6% | — |
| CVE-2024-38139 | HIGH 8.7 | microsoft dataverse Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2024-26822 | HIGH 8.7 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: set correct id, uid and cruid for multiuser automounts When uid, gid and cruid are not specified, we need to dynamically set them into the filesystem context used for automounti | 0.2% | — |
| CVE-2024-22093 | HIGH 8.7 | f5 big-ip_access_policy_manager When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions | 0.8% | — |
| CVE-2024-0056 | HIGH 8.7 | microsoft .net Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2023-48693 | HIGH 8.7 | microsoft azure_rtos_threadx Azure RTOS ThreadX is an advanced real-time operating system (RTOS) designed specifically for deeply embedded applications. An attacker can cause arbitrary read and write due to vulnerability in parameter checking mechanism in Azure RTOS ThreadX, which may le | 1.3% | — |
| CVE-2023-43746 | HIGH 8.7 | f5 big-ip_access_policy_manager When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG-IP external monitor on a BIG-IP system. A successful exploit can allow the attacker to cross a security bou | 0.4% | — |
| CVE-2023-34120 | HIGH 8.7 | zoom virtual_desktop_infrastructure Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher l | 0.1% | — |
| CVE-2023-29347 | HIGH 8.7 | microsoft windows_admin_center Windows Admin Center Spoofing Vulnerability | 1.9% | — |
| CVE-2023-21777 | HIGH 8.7 | microsoft azure_app_service_on_azure_stack Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2022-41800 | HIGH 8.7 | f5 big-ip_access_policy_manager In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to | 76.9% | — |
| CVE-2022-35243 | HIGH 8.7 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.5.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, using an | 0.7% | — |
| CVE-2022-27806 | HIGH 8.7 | f5 big-ip_access_policy_manager On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker assigned the Administrat | 1.5% | — |
| CVE-2022-25946 | HIGH 8.7 | f5 big-ip_access_policy_manager On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker with Administrator role | 0.4% | — |
| CVE-2021-42083 | HIGH 8.7 | osnexus quantastor An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager * open the ITSM tab * add a webhook with the URL/service token value ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab | 0.5% | — |
| CVE-2021-29678 | HIGH 8.7 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-Force ID: 199914. | 1.1% | — |
| CVE-2020-7808 | HIGH 8.7 | raonwiz raon_k_upload In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it. | 0.7% | — |
| CVE-2020-26072 | HIGH 8.7 | cisco iot_field_network_director A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the | 1.0% | — |
| CVE-2020-17147 | HIGH 8.7 | microsoft dynamics_365 Dynamics CRM Webclient Cross-site Scripting Vulnerability | 1.4% | — |
| CVE-2020-16946 | HIGH 8.7 | microsoft sharepoint_designer <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially | 1.6% | — |
| CVE-2020-16945 | HIGH 8.7 | microsoft sharepoint_enterprise_server <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially | 1.7% | — |
| CVE-2020-16944 | HIGH 8.7 | microsoft sharepoint_enterprise_server <p>This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.</p> <p>An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affec | 1.8% | — |
| CVE-2018-0436 | HIGH 8.7 | cisco webex_teams A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The vulnerability exists because the affected software performs insufficien | 1.3% | — |