56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.569 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2023-36802 | HIGH 7.8 | microsoft windows_10_1809 Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability | 26.1% | |
| CVE-2023-36761 | MED 6.5 | microsoft 365_apps Microsoft Word Information Disclosure Vulnerability | 19.0% | |
| CVE-2023-33246 | CRIT 9.8 | apache rocketmq For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attack | 96.6% | |
| CVE-2023-24489 | CRIT 9.8 | citrix sharefile_storage_zones_controller A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller. | 94.7% | |
| CVE-2023-38180 | HIGH 7.5 | fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability | 14.8% | |
| CVE-2023-3519 | CRIT 9.8 | ransomware citrix netscaler_application_delivery_controller Unauthenticated remote code execution | 99.7% | |
| CVE-2023-36884 | HIGH 7.5 | ransomware microsoft windows_10_1507 Windows Search Remote Code Execution Vulnerability | 98.9% | |
| CVE-2023-36874 | HIGH 7.8 | microsoft windows_10_1507 Windows Error Reporting Service Elevation of Privilege Vulnerability | 43.4% | |
| CVE-2023-35311 | HIGH 8.8 | microsoft 365_apps Microsoft Outlook Security Feature Bypass Vulnerability | 15.5% | |
| CVE-2023-32049 | HIGH 8.8 | microsoft windows_10_1607 Windows SmartScreen Security Feature Bypass Vulnerability | 4.2% | |
| CVE-2023-32046 | HIGH 7.8 | microsoft windows_10_1507 Windows MSHTML Platform Elevation of Privilege Vulnerability | 10.0% | |
| CVE-2023-20867 | LOW 3.9 | debian debian_linux A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. | 13.5% | |
| CVE-2023-20887 | CRIT 9.8 | vmware aria_operations_for_networks Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution. | 98.3% | |
| CVE-2016-9079 | HIGH 7.5 | debian debian_linux A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, a | 87.6% | |
| CVE-2016-0165 | HIGH 7.8 | microsoft windows_10_1507 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application | 13.8% | |
| CVE-2023-27997 | CRIT 9.8 | ransomware fortinet fortios A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, ver | 85.7% | |
| CVE-2023-3079 | HIGH 8.8 | apple macos Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 32.1% | |
| CVE-2016-6415 | HIGH 7.5 | cisco ios The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Assoc | 87.3% | |
| CVE-2004-1464 | MED 5.9 | cisco ios Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port. | 4.7% | |
| CVE-2016-8735 | CRIT 9.8 | apache tomcat Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this list | 90.3% | |
| CVE-2016-3427 | CRIT 9.8 | apache cassandra Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. | 92.3% | |
| CVE-2014-0196 | MED 5.5 | canonical ubuntu_linux The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privi | 22.5% | |
| CVE-2010-3904 | HIGH 7.8 | canonical ubuntu_linux The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via cr | 12.2% | |
| CVE-2023-29336 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 40.9% | |
| CVE-2021-45046 | CRIT 9.0 | ransomware apache log4j It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default | 100.0% |