58.306 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-17650 | HIGH 7.8 | fortinet forticlient An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local user of the system on which FortiClient is running to execute unauthorized code as root by bypassing a security ch | 0.4% | — |
| CVE-2019-1745 | HIGH 7.8 | cisco ios_xe A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attack | 0.4% | — |
| CVE-2019-17446 | HIGH 7.8 | eracent epa_agent An issue was discovered in Eracent EPA Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be used to start external programs with elevated permissions because of an Untrusted Search Path. | 0.3% | — |
| CVE-2019-17437 | HIGH 7.8 | paloaltonetworks pan-os An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser custom role user to elevate privileges and become superuser. This issue affects PAN-OS 7.1 versions prior to 7.1.25; 8.0 versions prior to 8.0 | 0.3% | — |
| CVE-2019-17388 | HIGH 7.8 | aviatrix vpn_client Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications. | 0.6% | — |
| CVE-2019-17387 | HIGH 7.8 | aviatrix vpn_client An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS. | 0.7% | — |
| CVE-2019-1735 | HIGH 7.8 | cisco nx-os A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device. The vulnerability is due to insufficient validation | 0.5% | — |
| CVE-2019-1726 | HIGH 7.8 | cisco nx-os A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted on an affected device, such as the NX-API. The vulnerability is due to insufficient validation of arguments pa | 0.4% | — |
| CVE-2019-17180 | HIGH 7.8 | valvesoftware steam_client Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Windows in the context of NT AUTHORITY\SYSTEM. This could lead to denial of service, elevation of privilege, or u | 0.7% | — |
| CVE-2019-17044 | HIGH 7.8 | bmc patrol_agent An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could allow an attacker with "patrol" privileges to elevate his/her privileges to the ones of the "root" user by specially crafting a shared library | 0.4% | — |
| CVE-2019-17009 | HIGH 7.8 | mozilla firefox When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system acces | 0.3% | — |
| CVE-2019-1682 | HIGH 7.8 | cisco application_policy_infrastructure_controller A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authenticated, local attacker to escalate privileges to root on an affected device. The vulnerability is due to insuffici | 0.4% | — |
| CVE-2019-1674 | HIGH 7.8 | cisco webex_meetings A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient v | 9.8% | — |
| CVE-2019-1664 | HIGH 7.8 | cisco hyperflex_hx_data_platform A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. The vulnerability is due to insufficient authentication controls. An attacker could exploit this v | 0.3% | — |
| CVE-2019-1654 | HIGH 7.8 | cisco ap-cos A vulnerability in the development shell (devshell) authentication for Cisco Aironet Series Access Points (APs) running the Cisco AP-COS operating system could allow an authenticated, local attacker to access the development shell without proper authentication | 0.4% | — |
| CVE-2019-1648 | HIGH 7.8 | cisco sd-wan A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included | 0.4% | — |
| CVE-2019-16471 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat Reader versions 2019.021.20056 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.3% | — |
| CVE-2019-16470 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat Reader versions 2019.021.20056 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that | 0.5% | — |
| CVE-2019-1646 | HIGH 7.8 | cisco sd-wan A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device configuration files. The vulnerability exists because user input is not properly sanitized for certain commands | 0.4% | — |
| CVE-2019-1641 | HIGH 7.8 | cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1.4% | — |
| CVE-2019-1640 | HIGH 7.8 | cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1.5% | — |
| CVE-2019-1639 | HIGH 7.8 | cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1.5% | — |
| CVE-2019-1638 | HIGH 7.8 | cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1.5% | — |
| CVE-2019-1637 | HIGH 7.8 | cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1.5% | — |
| CVE-2019-1636 | HIGH 7.8 | cisco webex_teams A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows operating | 46.9% | — |