58.465 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.465 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-6796 | MED 6.7 | cisco ios_xe A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an authenticated, local attacker to inject and execute arbitrary commands on the underlying operating system of an affected | 0.4% | — |
| CVE-2017-6794 | MED 6.7 | cisco meeting_server A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticate to the application with valid administ | 0.8% | — |
| CVE-2017-6773 | MED 6.7 | cisco asr_5000_software A vulnerability in the CLI of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, local attacker to bypass the CLI restrictions and execute commands on the underlying operating system. The v | 0.4% | — |
| CVE-2017-6748 | MED 6.7 | cisco web_security_appliance A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The attacker must authenticate with valid operator-level or administrator-leve | 0.8% | — |
| CVE-2017-6735 | MED 6.7 | cisco firesight_system_software A vulnerability in the backup and restore functionality of Cisco FireSIGHT System Software could allow an authenticated, local attacker to execute arbitrary code on a targeted system. More Information: CSCvc91092. Known Affected Releases: 6.2.0 6.2.1. | 0.4% | — |
| CVE-2017-6732 | MED 6.7 | cisco prime_network A vulnerability in the installation procedure for Cisco Prime Network Software could allow an authenticated, local attacker to elevate their privileges to root privileges. More Information: CSCvd47343. Known Affected Releases: 4.2(2.1)PP1 4.2(3.0)PP6 4.3(0.0)P | 0.3% | — |
| CVE-2017-6719 | MED 6.7 | cisco ios_xr A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection. More Information: CSCvb99406. Known Affected Releases: 6.2. | 0.7% | — |
| CVE-2017-6718 | MED 6.7 | cisco ios_xr A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level. More Information: CSCvb99384. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.11.3i.ROUT 6.2.1.29i.ROUT 6.2 | 0.4% | — |
| CVE-2017-6598 | MED 6.7 | cisco firepower_extensible_operating_system A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to exe | 0.4% | — |
| CVE-2017-6152 | MED 6.7 | f5 big-iq_centralized_management A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on the system, including the local admin account password. | 0.3% | — |
| CVE-2017-18551 | MED 6.7 | linux linux_kernel An issue was discovered in drivers/i2c/i2c-core-smbus.c in the Linux kernel before 4.14.15. There is an out of bounds write in the function i2c_smbus_xfer_emulated. | 0.4% | — |
| CVE-2017-15870 | MED 6.7 | paloaltonetworks globalprotect Palo Alto Networks GlobalProtect Agent before 4.0.3 allows attackers with administration rights on the local station to gain SYSTEM privileges via vectors involving "image path execution hijacking." | 0.4% | — |
| CVE-2017-1508 | MED 6.7 | ibm informix_dynamic_server IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges. IBM X-Force ID: 129620. | 0.3% | — |
| CVE-2017-1439 | MED 6.7 | ibm db2 IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128058. | 0.4% | — |
| CVE-2017-1438 | MED 6.7 | ibm db2 IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128057. | 0.4% | — |
| CVE-2017-12352 | MED 6.7 | cisco application_policy_infrastructure_controller A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could allow an authenticated, local attacker to gain elevated privileges and execute arbitrary commands with root privileges o | 0.4% | — |
| CVE-2017-12341 | MED 6.7 | cisco nx-os A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficie | 0.7% | — |
| CVE-2017-12334 | MED 6.7 | cisco nx-os A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficie | 0.6% | — |
| CVE-2017-12333 | MED 6.7 | cisco nx-os A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software image. The vulnerability is due to insufficient NX-OS signature verification for software images. An authentica | 0.2% | — |
| CVE-2017-12331 | MED 6.7 | cisco nx-os A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software patch. The vulnerability is due to insufficient NX-OS signature verification for software patches. An authentic | 0.2% | — |
| CVE-2017-12317 | MED 6.7 | cisco advanced_malware_protection The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in the application used to encrypt the conne | 0.3% | — |
| CVE-2017-12313 | MED 6.7 | cisco packet_tracer An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the in | 0.5% | — |
| CVE-2017-12312 | MED 6.7 | cisco advanced_malware_protection_for_endpoints An untrusted search path (aka DLL Preloading) vulnerability in the Cisco Immunet antimalware installer could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the installe | 0.5% | — |
| CVE-2017-12305 | MED 6.7 | cisco ip_phone_8800_series_firmware A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commands, aka Debug Shell Command Injection. The vulnerability is due to insufficient input validation. An attacker could exp | 0.8% | — |
| CVE-2017-12301 | MED 6.7 | cisco nx-os A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to in | 0.5% | — |