IT
56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

CVE Tracker

56.569 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2021-31805 CRIT 9.8 apache struts The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation 85.4%
CVE-2023-24955 HIGH 7.2 ransomware microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 85.4%
CVE-2019-3799 MED 6.5 oracle communications_cloud_native_core_policy Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A mali 85.3%
CVE-2022-28730 MED 6.1 apache jspwiki A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. This vulnerability leverages 85.3%
CVE-2022-27166 MED 6.1 apache jspwiki A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. 85.3%
CVE-2025-33053 HIGH 8.8 microsoft windows_10_1507 External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. 85.3%
CVE-2009-0075 HIGH 9.3 microsoft internet_explorer Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, ak 85.3%
CVE-2014-0322 HIGH 8.8 microsoft internet_explorer Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in J 85.2%
CVE-1999-1053 HIGH 7.5 apache http_server guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other c 85.2%
CVE-2020-26217 HIGH 8.0 apache activemq XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XSt 85.0%
CVE-2013-3906 HIGH 7.8 microsoft excel_viewer GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code via a crafted TIFF ima 85.0%
CVE-2006-3439 HIGH 10.0 microsoft windows_2000 Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314. 85.0%
CVE-2017-14491 CRIT 9.8 arista eos Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. 84.9%
CVE-2006-0026 MED 6.5 microsoft internet_information_server Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP). 84.9%
CVE-2021-1675 HIGH 7.8 ransomware microsoft windows_10_1507 Windows Print Spooler Remote Code Execution Vulnerability 84.8%
CVE-2004-0493 MED 6.4 apache http_server The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines wit 84.8%
CVE-2022-24697 CRIT 9.8 apache kylin Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any op 84.8%
CVE-2002-0649 HIGH 7.5 microsoft data_engine Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that 84.8%
CVE-2015-6132 HIGH 7.2 microsoft windows_10 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle library loading, which allows local users to gain privilege 84.7%
CVE-2023-36847 MED 5.3 juniper junos A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php 84.6%
CVE-2021-38294 CRIT 9.8 apache storm A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentic 84.5%
CVE-2026-3055 CRIT 9.8 citrix netscaler_application_delivery_controller Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread 84.5%
CVE-2018-1000006 HIGH 8.8 atom electron GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrar 84.4%
CVE-2015-1830 MED 5.0 apache activemq Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors. 84.4%
CVE-2023-29325 HIGH 8.1 microsoft windows_10_1507 Windows OLE Remote Code Execution Vulnerability 84.4%