IT
58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.046 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2020-24423 HIGH 7.0 adobe media_encoder Adobe Media Encoder version 14.4 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a 1.2%
CVE-2020-1033 MED 4.0 microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>An authenticated 1.2%
CVE-2017-8579 HIGH 7.0 microsoft windows_10 The DirectX component in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to run arbitrary code in kernel mode via a specially crafted application, aka "DirectX Elevation of Privilege Vulnerability." 1.2%
CVE-2017-7338 HIGH 7.5 fortinet fortiportal A password management vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to carry out information disclosure via the FortiAnalyzer Management View. 1.2%
CVE-2012-3074 HIGH 8.3 cisco telepresence_system_1300_65 An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging certain adjacency and sending a malformed request on TCP port 61460, aka Bug ID CSCtz38382. 1.2%
CVE-2026-26105 HIGH 8.1 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 1.2%
CVE-2024-47692 MED 6.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: return -EINVAL when namelen is 0 When we have a corrupted main.sqlite in /var/lib/nfs/nfsdcld/, it may result in namelen being 0, which will cause memdup_user() to return ZERO_SIZE_PTR 1.2%
CVE-2024-38263 HIGH 7.5 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability 1.2%
CVE-2023-25141 HIGH 7.5 apache sling_jcr_base Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility functions in RepositoryAccessor. The functions getRepository and getRepositoryFromURL allow an application to access 1.2%
CVE-2023-24977 HIGH 7.5 apache inlong Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7214 h 1.2%
CVE-2022-24947 HIGH 8.8 apache jspwiki Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later. 1.2%
CVE-2021-47324 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: watchdog: Fix possible use-after-free in wdt_startup() This module's remove path calls del_timer(). However, that function does not wait until the timer handler finishes. This means that the 1.2%
CVE-2021-47323 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: watchdog: sc520_wdt: Fix possible use-after-free in wdt_turnoff() This module's remove path calls del_timer(). However, that function does not wait until the timer handler finishes. This mea 1.2%
CVE-2021-22027 HIGH 7.5 vmware cloud_foundation The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leadin 1.2%
CVE-2019-12810 HIGH 7.8 estsoft alsee A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39. A specially crafted .PSD file can cause an out of bounds write vulnerability resulting in code execution. By persuading a victim to open a specially-crafted .PSD 1.2%
CVE-2012-4136 MED 6.8 cisco unified_computing_system The high-availability service in the Fabric Interconnect component in Cisco Unified Computing System (UCS) does not properly bind the cluster service to the management interface, which allows remote attackers to obtain sensitive information or cause a denial o 1.2%
CVE-2011-4232 MED 5.0 cisco unified_meetingplace The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists, which allows remote attackers to enumerate directory names via a series of queries, aka Bug ID CSCtt94070. 1.2%
CVE-2006-1864 MED 4.6 linux linux_kernel Directory traversal vulnerability in smbfs in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1863. 1.2%
CVE-2002-1491 MED 5.0 cisco vpn_5000_client The Cisco VPN 5000 Client for MacOS before 5.2.2 records the most recently used login password in plaintext when saving "Default Connection" settings, which could allow local users to gain privileges. 1.2%
CVE-2026-47827 HIGH 7.5 Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities 1.2%
CVE-2026-34355 HIGH 7.5 apache http_server A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue. 1.2%
CVE-2024-34365 CRIT 9.1 apache karaf_cave ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to 1.2%
CVE-2023-36037 HIGH 7.8 microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability 1.2%
CVE-2022-44644 MED 6.5 apache linkis In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files by connecting a rogue MySQL server, By adding allowLoadLocalInfile to true in the JDBC parameter. Therefore, the 1.2%
CVE-2022-30205 MED 6.6 microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability 1.2%