58.535 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.535 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-28710 | HIGH 7.5 | apache apache-airflow-providers-apache-spark Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider: before 4.0.1. | 2.2% | — |
| CVE-2021-21007 | HIGH 7.0 | adobe illustrator Adobe Illustrator version 25.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a | 2.2% | — |
| CVE-2018-4232 | MED 4.3 | apple icloud An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKi | 2.2% | — |
| CVE-2015-4302 | MED 6.4 | cisco firesight_system_software The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in a POST request, aka Bug ID CSCuu25390. | 2.2% | — |
| CVE-2021-25243 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain patch level information. | 2.2% | — |
| CVE-2021-25242 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain version and build information. | 2.2% | — |
| CVE-2021-25231 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific hotfix history file. | 2.2% | — |
| CVE-2017-12232 | MED 6.5 | cisco ios A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a d | 2.2% | |
| CVE-2012-6107 | MED 4.3 | apache apache_axis2\/c Apache Axis2/C does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2.2% | — |
| CVE-2020-1453 | HIGH 8.6 | microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP | 2.2% | — |
| CVE-2020-1452 | HIGH 8.6 | microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP | 2.2% | — |
| CVE-2024-38072 | HIGH 7.5 | microsoft windows_server_2016 Windows Remote Desktop Licensing Service Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-38041 | MED 5.5 | microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability | 2.2% | — |
| CVE-2024-20345 | MED 6.5 | cisco appdynamics_controller A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. This vulnerability is due to insufficient validation of user-suppli | 2.2% | — |
| CVE-2023-29328 | HIGH 8.8 | microsoft teams Microsoft Teams Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2002-0853 | MED 5.0 | cisco vpn_client Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a packet with a zero-length payload. | 2.2% | — |
| CVE-2019-1442 | MED 5.5 | microsoft sharepoint_server A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerab | 2.2% | — |
| CVE-2018-14616 | MED 5.5 | linux linux_kernel An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c when operating on a file in a corrupted f2fs image. | 2.2% | — |
| CVE-2016-7913 | HIGH 7.8 | canonical ubuntu_linux The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) via vectors involving omission of the firmware name from a certain data str | 2.2% | — |
| CVE-2022-33647 | HIGH 8.1 | microsoft windows_server_2008 Windows Kerberos Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2021-34474 | HIGH 8.0 | microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2015-0624 | MED 4.3 | cisco content_security_management_appliance The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur444 | 2.2% | — |
| CVE-2019-1463 | MED 5.5 | microsoft office An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1400. | 2.2% | — |
| CVE-2019-1400 | MED 5.5 | microsoft office An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1463. | 2.2% | — |
| CVE-2009-1758 | MED 5.0 | xen xen The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest OS by triggering a segmentatio | 2.2% | — |