58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-4073 | LOW 1.9 | debian debian_linux The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the (1) compat_sys_semctl, (2) compat_sys_msgct | 1.5% | — |
| CVE-2000-0777 | HIGH 7.2 | microsoft money The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability. | 1.5% | — |
| CVE-2000-0420 | HIGH 7.2 | microsoft windows_2000 The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data. | 1.5% | — |
| CVE-2026-21520 | HIGH 7.5 | microsoft copilot_studio Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector | 1.5% | — |
| CVE-2020-17046 | MED 5.5 | microsoft windows_10 Windows Error Reporting Denial of Service Vulnerability | 1.5% | — |
| CVE-2017-9796 | MED 5.3 | apache geode When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind parameter that allow read access to objects within unauthorize | 1.5% | — |
| CVE-2017-3822 | MED 5.3 | cisco secure_firewall_threat_defense A vulnerability in the logging subsystem of the Cisco Firepower Threat Defense (FTD) Firepower Device Manager (FDM) could allow an unauthenticated, remote attacker to add arbitrary entries to the audit log. This vulnerability affects Cisco Firepower Threat Def | 1.5% | — |
| CVE-2026-21260 | HIGH 7.5 | microsoft 365_apps Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | 1.5% | — |
| CVE-2022-20714 | HIGH 8.6 | cisco ios_xr A vulnerability in the data plane microcode of Lightspeed-Plus line cards for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the line card to reset. This vulnerability is due to the incorrect handlin | 1.5% | — |
| CVE-2021-27193 | CRIT 9.8 | netop vision_pro Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation. | 1.5% | — |
| CVE-2019-1640 | HIGH 7.8 | cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1.5% | — |
| CVE-2019-1639 | HIGH 7.8 | cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1.5% | — |
| CVE-2019-1638 | HIGH 7.8 | cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1.5% | — |
| CVE-2019-1637 | HIGH 7.8 | cisco webex_meetings_online A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1.5% | — |
| CVE-2011-0244 | MED 4.3 | apple safari WebKit in Apple Safari before 5.0.6 allows user-assisted remote attackers to read arbitrary files via vectors related to improper canonicalization of URLs within RSS feeds. | 1.5% | — |
| CVE-2010-4165 | MED 4.9 | linux linux_kernel The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MAXSEG (aka MSS) values, which allows local users to cause a denial of service (OOPS) via a setsockopt call that specifies a small value, lead | 1.5% | — |
| CVE-2021-40727 | HIGH 7.8 | adobe indesign Access of Memory Location After End of Buffer (CWE-788 | 1.5% | — |
| CVE-2020-4879 | CRIT 9.8 | ibm cognos_controller IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847. | 1.5% | — |
| CVE-2018-4437 | HIGH 8.8 | apple icloud Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9. | 1.5% | — |
| CVE-1999-0628 | MED 5.0 | freebsd freebsd The rwho/rwhod service is running, which exposes machine status and user information. | 1.5% | — |
| CVE-2024-23807 | CRIT 9.8 | apache xerces-c\+\+ The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD pro | 1.5% | — |
| CVE-2023-28983 | HIGH 8.8 | juniper junos_os_evolved An OS Command Injection vulnerability in gRPC Network Operations Interface (gNOI) server module of Juniper Networks Junos OS Evolved allows an authenticated, low privileged, network based attacker to inject shell commands and execute code. This issue affects J | 1.5% | — |
| CVE-2021-36742 | HIGH 7.8 | trendmicro apex_one A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obta | 1.5% | |
| CVE-2021-20373 | HIGH 7.5 | ibm db2 IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521. | 1.5% | — |
| CVE-2020-3926 | MED 6.1 | changingtec servisign An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter. | 1.5% | — |