CVE Tracker
Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.
1,542
Total CVEs
1,542
CISA KEV
1542
Critical & High
Mar 13, 2026
Last KEV Update
| CVE ID | Severity | Vendor | Description | Published | KEV |
|---|---|---|---|---|---|
| CVE-2021-30665 | High | AppleMultiple Products | Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Nov 3, 2021 | KEV |
| CVE-2021-30663 | High | AppleMultiple Products | Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Nov 3, 2021 | KEV |
| CVE-2021-30761 | High | AppleiOS | Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Nov 3, 2021 | KEV |
| CVE-2019-3396 | High | AtlassianConfluence Server and Data Server | Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution. | Nov 3, 2021 | KEV |
| CVE-2021-42258 | High | BQEBillQuick Web Suite | BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution. | Nov 3, 2021 | KEV |
| CVE-2020-3452 | High | CiscoAdaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. | Nov 3, 2021 | KEV |
| CVE-2020-3580 | High | CiscoAdaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information. | Nov 3, 2021 | KEV |
| CVE-2021-1498 | High | CiscoHyperFlex HX | Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user. | Nov 3, 2021 | KEV |
| CVE-2019-19781 | High | CitrixApplication Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution. | Nov 3, 2021 | KEV |
| CVE-2020-4430 | High | IBMData Risk Manager | IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system. | Nov 3, 2021 | KEV |
| CVE-2020-4427 | High | IBMData Risk Manager | IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. | Nov 3, 2021 | KEV |
| CVE-2021-31201 | High | MicrosoftEnhanced Cryptographic Provider | Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | KEV |
| CVE-2020-1020 | High | MicrosoftWindows | Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. | Nov 3, 2021 | KEV |
| CVE-2020-3566 | High | CiscoIOS XR | Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. | Nov 3, 2021 | KEV |
| CVE-2020-3569 | High | CiscoIOS XR | Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. | Nov 3, 2021 | KEV |
| CVE-2020-3161 | High | CiscoCisco IP Phones | Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition. | Nov 3, 2021 | KEV |
| CVE-2019-1653 | High | CiscoSmall Business RV320 and RV325 Routers | Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information. | Nov 3, 2021 | KEV |
| CVE-2018-0296 | High | CiscoAdaptive Security Appliance (ASA) | Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure. | Nov 3, 2021 | KEV |
| CVE-2019-13608 | High | CitrixStoreFront Server | Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information. | Nov 3, 2021 | KEV |
| CVE-2020-8193 | High | CitrixApplication Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation. | Nov 3, 2021 | KEV |