IT
58.535 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.535 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2020-9654 HIGH 7.8 adobe premiere_pro Adobe Premiere Pro versions 14.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . 2.1% —
CVE-2019-1760 MED 6.8 cisco ios_xe A vulnerability in Performance Routing Version 3 (PfRv3) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload. The vulnerability is due to the processing of malformed smart probe packets. An attacker c 2.1% —
CVE-2023-44361 MED 5.5 adobe acrobat Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such a 2.1% —
CVE-2018-0448 CRIT 9.8 cisco digital_network_architecture_center A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions. The vulnerability is due 2.1% —
CVE-2017-6653 HIGH 7.5 cisco identity_services_engine A vulnerability in the TCP throttling process for the GUI of the Cisco Identity Services Engine (ISE) 2.1(0.474) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device where the ISE GUI may fail to re 2.1% —
CVE-2017-6633 HIGH 7.5 cisco unified_computing_system A vulnerability in the TCP throttling process of Cisco UCS C-Series Rack Servers 3.0(0.234) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient rate-limiti 2.1% —
CVE-2017-3837 HIGH 8.1 cisco meeting_server An HTTP Packet Processing vulnerability in the Web Bridge interface of the Cisco Meeting Server (CMS), formerly Acano Conferencing Server, could allow an authenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confiden 2.1% —
CVE-2025-32709 HIGH 7.8 microsoft windows_10_1507 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 2.1%
CVE-2009-4919 HIGH 10.0 cisco asa_5580 Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to have an unspecified impact via long IKE attributes, aka Bug ID CSCsu43121. 2.1% —
CVE-2008-4210 MED 4.6 linux linux_kernel fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified othe 2.1% —
CVE-2022-39344 CRIT 9.8 microsoft azure_rtos_usbx Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. Prior to version 6.1.12, the USB DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memo 2.1% —
CVE-2021-37150 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. 2.1% —
CVE-2013-1150 HIGH 7.8 cisco adaptive_security_appliance The authentication-proxy implementation on Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31), 8.1 and 8.2 before 8.2(5.38), 8.3 before 8.3(2.37), 8.4 before 8.4(5.3), 8.5 and 8.6 before 8.6(1.10), 8.7 bef 2.1% —
CVE-2019-19448 HIGH 7.8 canonical ubuntu_linux In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left 2.1% —
CVE-2023-40272 HIGH 7.5 apache apache-airflow-providers-apache-spark Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server. It is recommended to upgrade 2.1% —
CVE-2022-38054 CRIT 9.8 apache airflow In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation. 2.1% —
CVE-2021-31471 MED 5.5 foxitsoftware 3d This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious f 2.1% —
CVE-2025-21350 MED 5.9 microsoft windows_10_1507 Windows Kerberos Denial of Service Vulnerability 2.1% —
CVE-2022-23274 HIGH 8.8 microsoft dynamics_gp Microsoft Dynamics GP Remote Code Execution Vulnerability 2.1% —
CVE-2015-7999 HIGH 8.1 citrix command_center Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.11 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. 2.1% —
CVE-2013-1333 HIGH 7.2 microsoft windows_7 Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overflow Vulnerability." 2.1% —
CVE-2023-33150 CRIT 9.6 microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability 2.1% —
CVE-2021-31983 HIGH 7.8 microsoft paint_3d Paint 3D Remote Code Execution Vulnerability 2.1% —
CVE-2021-1236 MED 5.3 cisco ios_xe Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection 2.1% —
CVE-2017-8654 MED 5.4 microsoft sharepoint_server Microsoft SharePoint Server 2010 Service Pack 2 allows a cross-site scripting (XSS) vulnerability when it does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability". 2.1% —