58.352 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.352 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-1340 | HIGH 8.4 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, | 1.5% | — |
| CVE-2012-5120 | HIGH 7.5 | google chrome Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, on 64-bit Linux platforms allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds access | 1.5% | — |
| CVE-2000-0771 | LOW 2.1 | microsoft windows_2000 Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability. | 1.5% | — |
| CVE-2024-30104 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2023-35296 | MED 6.5 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1.5% | — |
| CVE-2021-44183 | LOW 3.3 | adobe dimension Adobe Dimension versions 3.4.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue req | 1.5% | — |
| CVE-2020-35964 | MED 6.5 | ffmpeg ffmpeg track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing. | 1.5% | — |
| CVE-2019-1766 | HIGH 7.5 | cisco ip_phone_8800_firmware A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. | 1.5% | — |
| CVE-2013-3473 | HIGH 7.8 | cisco prime_central_for_hosted_collaboration_solution_assurance The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request | 1.5% | — |
| CVE-2024-49125 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2021-36001 | LOW 3.3 | adobe character_animator Adobe Character Animator version 4.2 (and earlier) is affected by an out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context o | 1.5% | — |
| CVE-2021-1230 | HIGH 8.6 | cisco nx-os A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a routing process to crash, which could lead to a denia | 1.5% | — |
| CVE-2020-4509 | HIGH 7.6 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 182364. | 1.5% | — |
| CVE-2019-1965 | HIGH 7.7 | cisco nx-os A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH process to fail to delete upon termination. This can lead to a build-up of VSH processes that overtime can deple | 1.5% | — |
| CVE-2016-3311 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted appl | 1.5% | — |
| CVE-2008-3358 | MED 4.3 | sap netweaver Cross-site scripting (XSS) vulnerability in Web Dynpro (WD) in the SAP NetWeaver portal, when Internet Explorer 7.0.5730 is used, allows remote attackers to inject arbitrary web script or HTML via a crafted URI, which causes the XSS payload to be reflected in | 1.5% | — |
| CVE-2003-1467 | MED 4.3 | phorum phorum Multiple cross-site scripting (XSS) vulnerabilities in (1) login.php, (2) register.php, (3) post.php, and (4) common.php in Phorum before 3.4.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | 1.5% | — |
| CVE-2024-49105 | HIGH 8.4 | microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2016-1497 | MED 4.9 | f5 big-ip_access_policy_manager The Configuration utility in F5 BIG-IP systems 11.0.x, 11.1.x, 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4 HF2, 1.6.x before 11.6.1, and 12.0.0 before HF1 allows remote administrators to read Access Policy Manager (APM) a | 1.5% | — |
| CVE-2011-2883 | HIGH 9.3 | citrix access_gateway The NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 attempts to validate signed DLLs by checking the certificate subject, not the signature, which allo | 1.5% | — |
| CVE-2009-3936 | MED 5.8 | citrix online_plug-in_for_mac Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Receiver for iPhone before 1.0.3, and ICA Java, Mac, UNIX, and Windows Clients for XenApp and XenDesktop allows remo | 1.5% | — |
| CVE-2025-29805 | HIGH 7.5 | microsoft outlook Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network. | 1.5% | — |
| CVE-2022-43982 | MED 6.1 | apache airflow In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. | 1.5% | — |
| CVE-2019-12476 | MED 6.8 | zohocorp manageengine_adselfservice_plus An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack u | 1.5% | — |
| CVE-2017-6703 | MED 5.9 | cisco prime_collaboration_provisioning A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, remote attacker to hijack another user's session. More Information: CSCvc90346. Known Affected Releases: 12.1. | 1.5% | — |