58.089 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.089 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-12297 | MED 5.0 | cisco webex_meeting_center A vulnerability in Cisco WebEx Meeting Center could allow an authenticated, remote attacker to initiate connections to arbitrary hosts, aka a "URL Redirection Vulnerability." The vulnerability is due to insufficient access control for HTTP traffic directed to | 1.2% | — |
| CVE-2017-11782 | HIGH 7.8 | microsoft windows_10 The Microsoft Server Block Message (SMB) on Microsoft Windows 10 1607 and Windows Server 2016, allows an elevation of privilege vulnerability when an attacker sends specially crafted requests to the server, aka "Windows SMB Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2016-3672 | HIGH 7.8 | canonical ubuntu_linux The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and bypass | 1.2% | — |
| CVE-2012-2857 | MED 6.8 | apple iphone_os Use-after-free vulnerability in the Cascading Style Sheets (CSS) DOM implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibl | 1.2% | — |
| CVE-2011-1236 | HIGH 7.8 | microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain | 1.2% | — |
| CVE-2026-26125 | HIGH 8.6 | microsoft payment_orchestrator_service Payment Orchestrator Service Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2025-21417 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2024-49128 | HIGH 8.1 | microsoft windows_server_2012 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.2% | — |
| CVE-2024-49119 | HIGH 8.1 | microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2024-38184 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2023-20197 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect c | 1.2% | — |
| CVE-2021-0275 | HIGH 8.8 | juniper junos A Cross-site Scripting (XSS) vulnerability in J-Web on Juniper Networks Junos OS allows an attacker to target another user's session thereby gaining access to the users session. The other user session must be active for the attack to succeed. Once successful, | 1.2% | — |
| CVE-2020-28169 | HIGH 7.0 | debian debian_linux The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM. | 1.2% | — |
| CVE-2017-6611 | MED 6.1 | cisco prime_infrastructure A vulnerability in the web framework code of Cisco Prime Infrastructure 2.2(2) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. The vulnerability is due | 1.2% | — |
| CVE-2016-6405 | MED 6.5 | cisco fog_director Cisco Fog Director 1.0(0) for IOx allows remote authenticated users to bypass intended access restrictions and write to arbitrary files via the Cartridge interface, aka Bug ID CSCuz89368. | 1.2% | — |
| CVE-2010-2579 | MED 5.0 | realnetworks realplayer The cook codec in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, RealPlayer Enterprise 2.1.2, Mac RealPlayer 11.0 through 11.1, and Linux RealPlayer 11.0.2.1744 does not properly initialize the number of channels, which allows atta | 1.2% | — |
| CVE-2026-49181 | HIGH 7.5 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network. | 1.2% | — |
| CVE-2024-21376 | CRIT 9.0 | microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-37581 | MED 5.4 | apache roller Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not have Roller configur | 1.2% | — |
| CVE-2022-25256 | MED 6.1 | sas web_report_studio SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button placed in the top left. The second affects the page t | 1.2% | — |
| CVE-2024-36268 | CRIT 9.8 | apache inlong Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.13.0 or cherry | 1.2% | — |
| CVE-2024-21325 | HIGH 7.8 | microsoft printer_metadata_troubleshooter_tool Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2021-40766 | LOW 3.3 | adobe character_animator Adobe Character Animator version 4.4 (and earlier versions) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of | 1.2% | — |
| CVE-2020-17102 | MED 5.5 | microsoft webp_image_extension WebP Image Extensions Information Disclosure Vulnerability | 1.2% | — |
| CVE-2017-15789 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x00000000000048e7." | 1.2% | — |