58.476 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.476 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-3943 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly link driver objects, which allows local users to gain privileg | 1.8% | — |
| CVE-2010-3942 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for copies from user mode, which allows local | 1.8% | — |
| CVE-2023-46819 | MED 5.3 | apache ofbiz Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09. Users are recommended to upgrade to version 18.12.09 | 1.8% | — |
| CVE-2023-21741 | HIGH 7.1 | microsoft 365_apps Microsoft Office Visio Information Disclosure Vulnerability | 1.8% | — |
| CVE-2022-43550 | CRIT 9.8 | jitsi jitsi A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the opportunity to remote execution. | 1.8% | — |
| CVE-2022-35830 | HIGH 8.1 | microsoft windows_server_2008 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2022-33127 | CRIT 9.8 | diffy_project diffy The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string. | 1.8% | — |
| CVE-2015-1647 | LOW 2.1 | microsoft windows_8.1 Virtual Machine Manager (VMM) in Hyper-V in Microsoft Windows 8.1 and Windows Server 2012 R2 allows guest OS users to cause a denial of service (VMM functionality loss) via a crafted application, aka "Windows Hyper-V DoS Vulnerability." | 1.8% | — |
| CVE-2021-1480 | HIGH 7.8 | cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these v | 1.8% | — |
| CVE-2019-0767 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To exploit this vulnerability, an authenticated attacker could run a specially crafted application, aka 'Windows Kernel Information Disclosure Vulne | 1.8% | — |
| CVE-2017-0521 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process | 1.8% | — |
| CVE-2014-3304 | MED 5.0 | cisco webex_meetings_server The OutlookAction Class in Cisco WebEx Meetings Server allows remote attackers to enumerate user accounts by entering crafted URLs and examining the returned messages, aka Bug ID CSCuj81722. | 1.8% | — |
| CVE-2013-3469 | MED 5.0 | cisco mobility_services_engine Cisco Mobility Services Engine does not properly set up the Oracle SSL service, which allows remote attackers to obtain an unauthenticated session to the database-replication port, and consequently obtain sensitive information, via an SSL connection, aka Bug I | 1.8% | — |
| CVE-1999-0505 | HIGH 7.2 | microsoft windows_2000 A Windows NT domain user or administrator account has a guessable password. | 1.8% | — |
| CVE-2024-43534 | MED 6.5 | microsoft windows_10_1507 Windows Graphics Component Information Disclosure Vulnerability | 1.8% | — |
| CVE-2017-7669 | HIGH 7.5 | apache hadoop In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands as root. | 1.8% | — |
| CVE-2016-10290 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Qualcomm shared memory driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged | 1.8% | — |
| CVE-2016-10285 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. | 1.8% | — |
| CVE-2014-3797 | MED 4.3 | vmware vcenter_server_appliance Cross-site scripting (XSS) vulnerability in VMware vCenter Server Appliance (vCSA) 5.1 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 1.8% | — |
| CVE-2014-0733 | MED 5.0 | cisco unified_communications_manager The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read ELM files via a direct request to a URL, aka Bu | 1.8% | — |
| CVE-2012-1367 | MED 5.0 | cisco ios The MallocLite implementation in Cisco IOS 12.0, 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (Route Processor crash) via a BGP UPDATE message with a modified local-preference (aka LOCAL_PREF) attribute length, aka Bug ID CSC | 1.8% | — |
| CVE-2010-2978 | HIGH 10.0 | cisco unified_wireless_network_solution_software Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 does not use an adequate message-digest algorithm for a self-signed certificate, which allows remote attackers to bypass intended access restrictions via vectors involving collisions, aka Bug ID | 1.8% | — |
| CVE-2009-3234 | MED 4.9 | linux linux_kernel Buffer overflow in the perf_copy_attr function in kernel/perf_counter.c in the Linux kernel 2.6.31-rc1 allows local users to cause a denial of service (crash) and execute arbitrary code via a "big size data" to the perf_counter_open system call. | 1.8% | — |
| CVE-2021-43800 | HIGH 7.5 | requarks wiki.js Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled on a Windows host. A malicious user can potentially read any file on t | 1.8% | — |
| CVE-2018-8477 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 1.8% | — |