IT
58.575 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.575 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2024-45507 CRIT 9.8 apache ofbiz Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue. 93.2% —
CVE-2012-1425 MED 4.3 antiy avl_sdk The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900 93.2% —
CVE-2022-33891 HIGH 8.8 apache spark The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in Ht 93.1%
CVE-2021-27905 CRIT 9.8 apache solr The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the loca 93.1% —
CVE-2016-4437 CRIT 9.8 apache aurora Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter. 93.0%
CVE-2005-1983 HIGH 10.0 microsoft windows_2000 Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as e 93.0% —
CVE-2019-15976 CRIT 9.8 cisco data_center_network_manager Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. F 92.8% —
CVE-2023-35628 HIGH 8.1 microsoft windows_10_1507 Windows MSHTML Platform Remote Code Execution Vulnerability 92.8% —
CVE-2022-0847 HIGH 7.8 fedoraproject fedora A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use th 92.8%
CVE-2022-21907 CRIT 9.8 microsoft windows_10 HTTP Protocol Stack Remote Code Execution Vulnerability 92.8% —
CVE-2024-45216 CRIT 9.8 apache solr Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, w 92.7% —
CVE-2023-28302 HIGH 7.5 microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 92.6% —
CVE-2023-21758 HIGH 7.5 microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 92.5% —
CVE-2022-24706 CRIT 9.8 apache couchdb In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including rec 92.5%
CVE-2009-3103 HIGH 10.0 microsoft windows_server_2008 Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) v 92.3% —
CVE-2022-41622 HIGH 8.8 f5 big-ip_access_policy_manager In all versions,  BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 92.3% —
CVE-2016-3427 CRIT 9.8 apache cassandra Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. 92.3%
CVE-2015-0359 HIGH 10.0 adobe flash_player Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CV 92.1% —
CVE-2010-1870 MED 5.0 apache struts The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly other products, uses a permissive whitelist, which allows remote attackers to modify server-side context objects 92.0% —
CVE-2019-0227 HIGH 7.5 apache axis A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from sou 91.9% —
CVE-2010-0249 HIGH 8.8 microsoft internet_explorer Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers 91.9%
CVE-2017-12629 CRIT 9.8 apache solr Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnera 91.9% —
CVE-2025-64446 CRIT 9.8 fortinet fortiweb A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands 91.8%
CVE-2024-5910 CRIT 9.8 paloaltonetworks expedition Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichm 91.8%
CVE-2021-42321 HIGH 8.8 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 91.7%