58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-21959 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-21958 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-21892 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-20793 | MED 6.8 | cisco roomos A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device. This vulnerabili | 0.4% | — |
| CVE-2022-20774 | MED 6.8 | cisco ip_phone_6825_firmware A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-base | 0.4% | — |
| CVE-2022-20758 | MED 6.8 | cisco ios_xr A vulnerability in the implementation of the Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the | 1.2% | — |
| CVE-2022-20694 | MED 6.8 | cisco ios_xe A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Border Gateway Protocol (BGP) process to crash, resulting in a denial of servic | 1.2% | — |
| CVE-2022-20679 | MED 6.8 | cisco ios_xe A vulnerability in the IPSec decryption routine of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to buffer exhaustion tha | 1.3% | — |
| CVE-2022-1789 | MED 6.8 | debian debian_linux With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference. | 0.3% | — |
| CVE-2022-0020 | MED 6.8 | paloaltonetworks cortex_xsoar A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on | 1.7% | — |
| CVE-2021-44167 | MED 6.8 | fortinet forticlient An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6.4.7 and below, 7.0.2 and below may allow an unauthenticated attacker to access sensitive information in log fi | 0.5% | — |
| CVE-2021-42284 | MED 6.8 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 3.7% | — |
| CVE-2021-42274 | MED 6.8 | microsoft windows_10 Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability | 0.7% | — |
| CVE-2021-4203 | MED 6.8 | linux linux_kernel A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal ker | 1.7% | — |
| CVE-2021-41342 | MED 6.8 | microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2021-40114 | MED 6.8 | cisco secure_firewall_management_center Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is d | 2.4% | — |
| CVE-2021-39234 | MED 6.8 | apache ozone In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL. | 1.4% | — |
| CVE-2021-38204 | MED 6.8 | debian debian_linux drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations. | 0.3% | — |
| CVE-2021-36189 | MED 6.8 | fortinet forticlient_enterprise_management_server A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information disclosure via inspecting browser decrypted data | 0.4% | — |
| CVE-2021-35248 | MED 6.8 | solarwinds orion_platform It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings. | 0.9% | — |
| CVE-2021-35244 | MED 6.8 | solarwinds orion_platform The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file uploa | 5.8% | — |
| CVE-2021-34703 | MED 6.8 | cisco ios A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and Cisco IOS XE Software could allow an attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability i | 1.2% | — |
| CVE-2021-34534 | MED 6.8 | microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-34497 | MED 6.8 | microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2021-34480 | MED 6.8 | microsoft windows_10 Scripting Engine Memory Corruption Vulnerability | 33.9% | — |