IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2013-6944 MED 4.3 citrix netscaler_application_delivery_controller_firmware Cross-site scripting (XSS) vulnerability in the user interface in the AAA TM vServer in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to inject arbitrary 1.5% —
CVE-2002-1447 HIGH 7.2 cisco vpn_client Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name in a connect argument. 1.5% —
CVE-2024-29735 MED 5.3 apache airflow Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 through 2.8.3. Airflow's local file task handler in Airflow incorrectly set permissions for all parent folders of log folder, in default configur 1.5% —
CVE-2023-6356 MED 6.5 debian debian_linux A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver and causing ker 1.5% —
CVE-2020-19510 CRIT 9.8 textpattern textpattern Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php. 1.5% —
CVE-2018-6634 CRIT 9.8 parsecgaming parsec A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized users to maintain access to an account. 1.5% —
CVE-2017-8650 MED 5.4 microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to exploit a security feature bypass due to Microsoft Edge not properly enforcing same-origin policies, aka "Microsoft Edge Security Feature Bypass Vulnerability". 1.5% —
CVE-2017-8493 MED 5.5 microsoft windows_10 Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to set variables that are either read-only or require authentication when Windows fails to enforce case sensitivi 1.5% —
CVE-2015-2418 MED 6.9 microsoft malicious_software_removal_tool Race condition in Microsoft Malicious Software Removal Tool (MSRT) before 5.26 allows local users to gain privileges via a crafted DLL, aka "MSRT Race Condition Vulnerability." 1.5% —
CVE-2007-3463 MED 4.6 microsoft windows_xp Microsoft Windows XP SP2 allows local users, who have sessions created by another user's RunAs (run as) command, to kill arbitrary processes of this other user, as demonstrated by the taskkill program. NOTE: the researcher claims a vendor dispute in which the 1.5% —
CVE-2024-29995 HIGH 8.1 microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability 1.5% —
CVE-2023-24922 MED 6.5 microsoft dynamics_365 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability 1.5% —
CVE-2023-24906 MED 6.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.5% —
CVE-2023-24883 MED 6.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.5% —
CVE-2023-24870 MED 6.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.5% —
CVE-2023-24863 MED 6.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.5% —
CVE-2023-24857 MED 6.5 microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.5% —
CVE-2021-45059 LOW 3.3 adobe indesign Adobe InDesign version 16.4 (and earlier) is affected by a use-after-free vulnerability in the processing of a JPEG2000 file that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex 1.5% —
CVE-2019-6637 MED 6.5 f5 big-ip_application_security_manager On BIG-IP (ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, Application logic abuse of ASM REST endpoints can lead to instability of BIG-IP system. Exploitation of this issue causes excessive memory consumption which results in the Li 1.5% —
CVE-2019-0646 MED 5.4 microsoft team_foundation_server A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka "Team Foundation Server Cross-site Scripting Vulnerability." This affects Team. 1.5% —
CVE-2019-0624 MED 5.4 microsoft skype_for_business A spoofing vulnerability exists when a Skype for Business 2015 server does not properly sanitize a specially crafted request, aka "Skype for Business 2015 Spoofing Vulnerability." This affects Skype. 1.5% —
CVE-2009-0083 HIGH 7.2 microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invalid Pointer 1.5% —
CVE-2023-21703 MED 6.5 microsoft azure_data_box_gateway Azure Data Box Gateway Remote Code Execution Vulnerability 1.5% —
CVE-2021-37980 HIGH 7.4 debian debian_linux Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows. 1.5% —
CVE-2021-24096 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.5% —