IT
58.318 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.318 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-20656 MED 6.5 cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. To exploit this vulnerability, the attacker must have valid crede 1.7% —
CVE-2022-1128 MED 6.5 google chrome Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page. 0.7% —
CVE-2022-0807 MED 6.5 google chrome Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. 0.9% —
CVE-2022-0806 MED 6.5 google chrome Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page. 1.0% —
CVE-2022-0804 MED 6.5 google chrome Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. 0.9% —
CVE-2022-0803 MED 6.5 google chrome Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page. 0.9% —
CVE-2022-0802 MED 6.5 google chrome Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. 0.9% —
CVE-2022-0337 MED 6.5 google chrome Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page. (Chrome security severity: High) 1.3% —
CVE-2022-0011 MED 6.5 paloaltonetworks pan-os PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on your rules) regardless of their associated URL category. This is done by creating a custom URL category list or 0.7% —
CVE-2021-45230 MED 6.5 apache airflow In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for. 1.7% —
CVE-2021-44451 MED 6.5 apache superset Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher. 7.9% —
CVE-2021-44230 MED 6.5 portswigger burp_suite PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows accoun 1.0% —
CVE-2021-44145 MED 6.5 apache nifi In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information. 1.7% —
CVE-2021-44050 MED 6.5 broadcom ca_network_flow_analysis CA Network Flow Analysis (NFA) 21.2.1 and earlier contain a SQL injection vulnerability in the NFA web application, due to insufficient input validation, that could potentially allow an authenticated user to access sensitive data. 0.9% —
CVE-2021-43244 MED 6.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 0.8% —
CVE-2021-43216 MED 6.5 microsoft windows_10 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability 3.2% —
CVE-2021-42809 MED 6.5 thalesgroup sentinel_protection_installer Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code. 0.3% —
CVE-2021-42808 MED 6.5 thalesgroup sentinel_protection_installer Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges. 0.2% —
CVE-2021-42305 MED 6.5 microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability 7.9% —
CVE-2021-42293 MED 6.5 microsoft 365_apps Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability 2.8% —
CVE-2021-42250 MED 6.5 apache superset Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs. 1.8% —
CVE-2021-41973 MED 6.5 apache mina In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update M 4.6% —
CVE-2021-41972 MED 6.5 apache superset Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way. 1.5% —
CVE-2021-41767 MED 6.5 apache guacamole Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact w 1.9% —
CVE-2021-41571 MED 6.5 apache pulsar In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API get-message-by-id requires the user to input a topic and a ledger id. The ledger id is a pointer to the data, 1.7% —