58.614 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.614 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2004-1111 | MED 5.0 | cisco 7200_router Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause | 2.3% | — |
| CVE-2022-26818 | MED 6.6 | microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-21874 | HIGH 7.8 | microsoft windows_10 Windows Security Center API Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-31180 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2015-3616 | CRIT 9.8 | fortinet fortimanager_firmware SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to execute arbitrary commands via unspecified parameters. | 2.3% | — |
| CVE-2015-2549 | HIGH 7.2 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka | 2.3% | — |
| CVE-2025-54916 | HIGH 7.8 | microsoft windows_10_1507 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 2.3% | — |
| CVE-2024-41869 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user | 2.3% | — |
| CVE-2022-22976 | MED 5.3 | netapp active_iq_unified_manager Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to | 2.3% | — |
| CVE-2017-7664 | CRIT 10.0 | apache openmeetings Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0. | 2.3% | — |
| CVE-2015-6260 | HIGH 7.5 | zyxel gs1900-10hp_firmware Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote attackers to cause a denial of service (SNMP application restart) via a crafted packet, aka Bug ID CSCut84645. | 2.3% | — |
| CVE-2015-3099 | MED 5.0 | adobe air Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and | 2.3% | — |
| CVE-2015-3098 | MED 5.0 | adobe air Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and | 2.3% | — |
| CVE-2025-21176 | HIGH 8.8 | microsoft .net .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-38542 | MED 5.9 | apache james Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information. | 2.3% | — |
| CVE-2020-9596 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass. | 2.3% | — |
| CVE-2020-9592 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass. | 2.3% | — |
| CVE-2018-3939 | HIGH 8.8 | foxitsoftware foxit_reader An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution | 2.3% | — |
| CVE-2011-0788 | HIGH 7.6 | sun jdk Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, a | 2.3% | — |
| CVE-2021-42726 | HIGH 7.8 | adobe media_encoder Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to e | 2.3% | — |
| CVE-2017-12362 | MED 6.5 | cisco meeting_server A vulnerability in Cisco Meeting Server versions prior to 2.2.2 could allow an authenticated, remote attacker to cause the system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to video calls being made on systems with a | 2.3% | — |
| CVE-2014-1663 | MED 5.0 | citrix xenmobile_device_manager Unspecified vulnerability in Citrix XenMobile Device Manager server (formerly Zenprise Device Manager server) 8.5, 8.6, and MDM 8.0.1 allows remote attackers to obtain sensitive information via unknown vectors. | 2.3% | — |
| CVE-2022-20718 | MED 5.5 | cisco ios_xe Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system | 2.4% | — |
| CVE-2021-21008 | HIGH 7.0 | adobe animate Adobe Animate version 21.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mali | 2.4% | — |
| CVE-2019-12648 | HIGH 8.8 | cisco ios A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access to the Guest Operating System (Guest OS) running on an affected device. The vulnerability is due to incorrect ro | 2.4% | — |