58.007 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.007 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-11790 | HIGH 7.8 | apache openoffice When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic Overflow at a string length calculation. | 1.0% | — |
| CVE-2017-8593 | HIGH 7.0 | microsoft windows_10 Microsoft Win32k in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to | 1.0% | — |
| CVE-2011-4734 | HIGH 7.5 | parallels parallels_plesk_panel Multiple SQL injection vulnerabilities in the Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by file-manager/ and certain other files. | 1.0% | — |
| CVE-2011-4725 | HIGH 7.5 | parallels parallels_plesk_panel Multiple SQL injection vulnerabilities in the Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by login_up.php3 and certai | 1.0% | — |
| CVE-2026-20849 | HIGH 7.5 | microsoft windows_10_1607 Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2023-42031 | MED 4.9 | ibm cics_tx IBM TXSeries for Multiplatforms, 8.1, 8.2, and 9.1, CICS TX Standard CICS TX Advanced 10.1 and 11.1 could allow a privileged user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 266016. | 1.0% | — |
| CVE-2023-35908 | MED 6.5 | apache airflow Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected | 1.0% | — |
| CVE-2022-22433 | HIGH 7.5 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS | 1.0% | — |
| CVE-2022-0796 | HIGH 8.8 | google chrome Use after free in Media in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1.0% | — |
| CVE-2020-25668 | HIGH 7.0 | debian debian_linux A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op. | 1.0% | — |
| CVE-2020-1071 | MED 6.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialog. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit this vulnerability | 1.0% | — |
| CVE-2018-6756 | HIGH 7.8 | mcafee true_key Authentication Abuse vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute unauthorized commands via specially crafted malware. | 1.0% | — |
| CVE-2026-50470 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-50463 | HIGH 7.5 | microsoft windows_10_1809 Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-47633 | HIGH 7.5 | microsoft cost_management Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-32952 | MED 5.3 | microsoft go-ntlmssp go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport | 1.0% | — |
| CVE-2023-29255 | HIGH 7.5 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compiling a variation of an anonymous block. IBM X-Force ID: 251991. | 1.0% | — |
| CVE-2023-26021 | HIGH 7.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service as the server may crash when compiling a specially crafted SQL query using a LIMIT clause. IBM X-Force ID: 247864. | 1.0% | — |
| CVE-2022-34028 | HIGH 7.5 | f5 njs Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h. | 1.0% | — |
| CVE-2022-23909 | HIGH 7.8 | gimmal sherpa_connector_service There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file. | 1.0% | — |
| CVE-2021-22982 | HIGH 7.2 | f5 big-ip_domain_name_system On BIG-IP DNS and GTM version 13.1.x before 13.1.0.4, and all versions of 12.1.x and 11.6.x, big3d does not securely handle and parse certain payloads resulting in a buffer overflow. Note: Software versions which have reached End of Software Development (EoSD) | 1.0% | — |
| CVE-2019-6686 | MED 5.3 | f5 big-ip_local_traffic_manager On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, the Traffic Management Microkernel (TMM) might stop responding after the total number of diameter connections and pending messages on a single virtual server has reached 32K. | 1.0% | — |
| CVE-2019-16004 | MED 6.5 | cisco vision_dynamic_signage_director A vulnerability in the REST API endpoint of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to missing authentication on some of the API calls. An at | 1.0% | — |
| CVE-2018-0600 | HIGH 7.8 | sony playmemories_home Untrusted search path vulnerability in the installer of PlayMemories Home for Windows ver.5.5.01 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 1.0% | — |
| CVE-1999-1166 | HIGH 7.2 | linux linux_kernel Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory. | 1.0% | — |