IT
58.515 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.515 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2015-5349 HIGH 7.8 apache directory_studio The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported 2.1% —
CVE-2018-19450 HIGH 7.8 foxitsoftware foxit_pdf_sdk_activex A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a launch action. An attacker can leverage this to gain remote code execution. 2.1% —
CVE-2016-7912 HIGH 7.8 linux linux_kernel Use-after-free vulnerability in the ffs_user_copy_worker function in drivers/usb/gadget/function/f_fs.c in the Linux kernel before 4.5.3 allows local users to gain privileges by accessing an I/O data structure after a certain callback call. 2.1% —
CVE-2015-0635 HIGH 9.0 cisco ios The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to spoof Autonomic Networking Registration Authority (ANRA) responses, an 2.1% —
CVE-2016-9313 HIGH 7.8 linux linux_kernel security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly ha 2.1% —
CVE-2016-1276 MED 5.9 juniper junos Juniper Junos OS before 12.1X46-D50, 12.1X47 before 12.1X47-D23, 12.3X48 before 12.3X48-D25, and 15.1X49 before 15.1X49-D40 on a High-End SRX-Series chassis system with one or more Application Layer Gateways (ALGs) enabled allow remote attackers to cause a den 2.1% —
CVE-2013-5532 MED 5.0 cisco unified_ip_phone_9951 Buffer overflow in the web-application interface on Cisco 9900 IP phones allows remote attackers to cause a denial of service (webapp interface outage) via long values in unspecified fields, aka Bug ID CSCuh10343. 2.1% —
CVE-2007-0968 HIGH 9.0 cisco firewall_services_module Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in an ACL to be improperly evaluated, which allows remote authenticated users to bypass intended certain ACL prot 2.1% —
CVE-2006-0488 LOW 2.1 microsoft windows_2000 The VDM (Virtual DOS Machine) emulation environment for MS-DOS applications in Windows 2000, Windows XP SP2, and Windows Server 2003 allows local users to read the first megabyte of memory and possibly obtain sensitive information, as demonstrated by dumper.as 2.1% —
CVE-2021-1726 HIGH 8.0 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 2.1% —
CVE-2020-0965 HIGH 7.8 microsoft windows_10 A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. 2.1% —
CVE-2014-3309 MED 5.0 cisco ios The NTP implementation in Cisco IOS and IOS XE does not properly support use of the access-group command for a "deny all" configuration, which allows remote attackers to bypass intended restrictions on time synchronization via a standard query, aka Bug ID CSCu 2.1% —
CVE-2012-4090 MED 4.0 cisco nexus_7000 The management interface in Cisco NX-OS on Nexus 7000 devices allows remote authenticated users to obtain sensitive configuration-file information by leveraging the network-operator role, aka Bug ID CSCti09089. 2.1% —
CVE-2023-51653 CRIT 9.8 apache hertzbeat Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect` is vulnerable to JNDI injection. The corresponding interface is `/api/monitor/detect`. If there is a URL field, the address will be used b 2.1% —
CVE-2022-21979 MED 4.8 microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability 2.1% —
CVE-2021-40710 HIGH 7.8 adobe premiere_pro Adobe Premiere Pro version 15.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .svg file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required 2.1% —
CVE-2021-1639 HIGH 7.0 microsoft visual_studio_2017 Visual Studio Code Remote Code Execution Vulnerability 2.1% —
CVE-2020-15476 HIGH 7.5 debian debian_linux In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c. 2.1% —
CVE-2016-1463 HIGH 7.5 cisco firesight_system_software Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the header of an HTTP packet, aka Bug ID CSCuz20737. 2.1% —
CVE-2022-27483 HIGH 7.2 fortinet fortianalyzer A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x and FortiAnalyzer version 7.0.0 through 7.0.3, version 6.4.0 through 6.4.7, 2.1% —
CVE-2018-3940 HIGH 8.8 foxitsoftware phantompdf An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused. An attacker needs to trick the user t 2.1% —
CVE-2021-1487 HIGH 8.8 cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability is due to in 2.1% —
CVE-2003-1132 MED 5.0 cisco content_services_switch_11000 The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0 ("No Error"), which allows remote attackers to cause a denia 2.1% —
CVE-2023-36764 HIGH 8.8 microsoft sharepoint_server Microsoft SharePoint Server Elevation of Privilege Vulnerability 2.1% —
CVE-2022-35827 HIGH 8.8 microsoft visual_studio Visual Studio Remote Code Execution Vulnerability 2.1% —