58.586 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.586 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-0661 | HIGH 8.3 | cisco telepresence_system_1000 The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX1310 65, and TX9xxx before 6.0.4(11), allows remote attackers to execute arbitrary commands or cause a denial of s | 2.3% | — |
| CVE-2018-0385 | HIGH 7.5 | cisco secure_firewall_management_center A vulnerability in the detection engine parsing of Security Socket Layer (SSL) protocol packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpected | 2.3% | — |
| CVE-2018-0139 | HIGH 8.6 | cisco unified_customer_voice_portal A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause the IVR connection to disconnect, creating a system-wide denial of se | 2.3% | — |
| CVE-2016-1715 | MED 6.6 | mcafee application_control The swin.sys kernel driver in McAfee Application Control (MAC) 6.1.0 before build 706, 6.1.1 before build 404, 6.1.2 before build 449, 6.1.3 before build 441, and 6.2.0 before build 505 on 32-bit Windows platforms allows local users to cause a denial of servic | 2.3% | — |
| CVE-2022-24522 | MED 6.5 | microsoft skype_extension Skype Extension for Chrome Information Disclosure Vulnerability | 2.3% | — |
| CVE-2018-15328 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not handled by the BIG-IP system Secure Vault | 2.3% | — |
| CVE-2009-0619 | HIGH 7.8 | cisco session_border_controller Unspecified vulnerability in the Session Border Controller (SBC) before 3.0(2) for Cisco 7600 series routers allows remote attackers to cause a denial of service (SBC card reload) via crafted packets to TCP port 2000. | 2.3% | — |
| CVE-2024-52338 | CRIT 9.8 | apache arrow Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for | 2.3% | — |
| CVE-2021-36019 | LOW 3.3 | adobe after_effects Adobe After Effects version 18.2.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of | 2.3% | — |
| CVE-2021-36018 | LOW 3.3 | adobe after_effects Adobe After Effects version 18.2.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of | 2.3% | — |
| CVE-2021-35995 | LOW 3.3 | adobe after_effects Adobe After Effects version 18.2.1 (and earlier) is affected by an Improper input validation vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the cont | 2.3% | — |
| CVE-2021-26437 | MED 5.5 | microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability | 2.3% | — |
| CVE-2020-3299 | MED 5.8 | cisco secure_firewall_threat_defense Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured File Policy for HTTP. The vulnerability is due to incorrect detection of modified HTTP packets use | 2.3% | — |
| CVE-2019-6485 | MED 5.9 | citrix netscaler_application_delivery_controller_firmware Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build | 2.3% | — |
| CVE-2017-8628 | MED 6.8 | microsoft windows_10 Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703 allows a spoofing vulnerability due to Microsoft's implementation of the Bluetooth stack, aka "Microsoft Bluetooth Driver Spoof | 2.3% | — |
| CVE-2015-2060 | MED 5.3 | cabextract_project cabextract cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash. | 2.3% | — |
| CVE-2009-4378 | MED 4.3 | wireshark wireshark The IPMI dissector in Wireshark 1.2.0 through 1.2.4 on Windows allows remote attackers to cause a denial of service (crash) via a crafted packet, related to "formatting a date/time using strftime." | 2.3% | — |
| CVE-2024-38232 | HIGH 7.5 | microsoft windows_10_1607 Windows Networking Denial of Service Vulnerability | 2.3% | — |
| CVE-2024-20670 | HIGH 8.1 | microsoft outlook Outlook for Windows Spoofing Vulnerability | 2.3% | — |
| CVE-2023-44336 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in | 2.3% | — |
| CVE-2022-35824 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2018-18999 | HIGH 7.3 | advantech webaccess\/scada WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user supplied input may allow an attacker to cause the overflow of a buffer on the stack. | 2.3% | — |
| CVE-2015-6406 | MED 4.0 | cisco emergency_responder Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authenticated users to write to arbitrary files via a crafted filename, aka Bug ID CSCuv21781. | 2.3% | — |
| CVE-2014-3323 | MED 4.0 | cisco unified_contact_center_enterprise Directory traversal vulnerability in Cisco Unified Contact Center Enterprise allows remote authenticated users to read arbitrary web-root files via a crafted URL, aka Bug ID CSCun25262. | 2.3% | — |
| CVE-2011-2806 | HIGH 10.0 | google chrome Google Chrome before 13.0.782.215 on Windows does not properly handle vertex data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. | 2.3% | — |