58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-20787 | MED 5.7 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an authenticated, remote attacker to conduct a cross-site request for | 0.5% | — |
| CVE-2021-42288 | MED 5.7 | microsoft windows_10 Windows Hello Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2021-41355 | MED 5.7 | microsoft .net .NET Core and Visual Studio Information Disclosure Vulnerability | 20.3% | — |
| CVE-2021-38632 | MED 5.7 | microsoft windows_10 Windows BitLocker Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2021-34466 | MED 5.7 | microsoft windows_10 Windows Hello Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2021-33114 | MED 5.7 | intel ac_1550_firmware Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an authenticated user to potentially enable denial of service via adjacent access. | 0.5% | — |
| CVE-2021-31965 | MED 5.7 | microsoft sharepoint_foundation Microsoft SharePoint Server Information Disclosure Vulnerability | 4.5% | — |
| CVE-2021-28444 | MED 5.7 | microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability | 1.7% | — |
| CVE-2021-27079 | MED 5.7 | microsoft windows_10 Windows Media Photo Codec Information Disclosure Vulnerability | 2.9% | — |
| CVE-2021-24114 | MED 5.7 | microsoft teams Microsoft Teams iOS Information Disclosure Vulnerability | 3.2% | — |
| CVE-2021-1708 | MED 5.7 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 3.4% | — |
| CVE-2021-0129 | MED 5.7 | bluez bluez Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access. | 0.8% | — |
| CVE-2020-5414 | MED 5.7 | vmware operations_manager VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware Tanzu Operations Man | 0.7% | — |
| CVE-2020-3537 | MED 5.7 | cisco jabber A vulnerability in Cisco Jabber for Windows software could allow an authenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sen | 1.3% | — |
| CVE-2020-27825 | MED 5.7 | debian debian_linux A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could e | 0.3% | — |
| CVE-2020-16983 | MED 5.7 | microsoft azure_sphere Azure Sphere Tampering Vulnerability | 0.7% | — |
| CVE-2020-15707 | MED 5.7 | canonical ubuntu_linux Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow | 1.6% | — |
| CVE-2020-10146 | MED 5.7 | microsoft teams The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as authentication tokens and to possibly execute arbitrary commands | 2.0% | — |
| CVE-2019-19160 | MED 5.7 | cabsoftware reportexpress_proplus Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp). | 0.6% | — |
| CVE-2019-0950 | MED 5.7 | microsoft sharepoint_foundation A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019- | 2.5% | — |
| CVE-2019-0949 | MED 5.7 | microsoft sharepoint_foundation A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0950, CVE-2019- | 2.5% | — |
| CVE-2018-0414 | MED 5.7 | cisco secure_access_control_server_solution_engine A vulnerability in the web-based UI of Cisco Secure Access Control Server could allow an authenticated, remote attacker to gain read access to certain information in an affected system. The vulnerability is due to improper handling of XML External Entities (XX | 1.8% | — |
| CVE-2018-0029 | MED 5.7 | juniper junos While experiencing a broadcast storm, placing the fxp0 interface into promiscuous mode via the 'monitor traffic interface fxp0' can cause the system to crash and restart (vmcore). This issue only affects Junos OS 15.1 and later releases, and affects both singl | 0.6% | — |
| CVE-2017-6775 | MED 5.7 | cisco asr_5000_software A vulnerability in the CLI of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, local attacker to elevate their privileges to admin-level privileges. The vulnerability is due to incorrect | 0.3% | — |
| CVE-2017-5042 | MED 5.7 | debian debian_linux Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any pl | 0.4% | — |