58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-39860 | MED 5.5 | adobe acrobat Acrobat Pro DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive us | 2.4% | — |
| CVE-2021-3178 | MED 6.5 | debian debian_linux fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export | 2.4% | — |
| CVE-2020-3125 | CRIT 9.8 | cisco adaptive_security_appliance_software A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to impersonate the Kerberos key distribution center (KDC) and bypass authentication on an affected device | 2.4% | — |
| CVE-2020-16939 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit the vulnerability, an attacker would first hav | 2.4% | — |
| CVE-2016-5308 | MED 5.5 | symantec client_intrusion_detection_system The Client Intrusion Detection System (CIDS) driver before 15.0.6 in Symantec Endpoint Protection (SEP) and before 15.1.2 in Norton Security allows remote attackers to cause a denial of service (memory corruption and system crash) via a malformed Portable Exec | 2.4% | — |
| CVE-2021-36074 | LOW 3.3 | adobe bridge Adobe Bridge versions 11.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue require | 2.4% | — |
| CVE-2021-36071 | LOW 3.3 | adobe bridge Adobe Bridge versions 11.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue require | 2.4% | — |
| CVE-2016-4728 | HIGH 8.8 | apple iphone_os WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 mishandles error prototypes, which allows remote attackers to execute arbitrary code via a crafted web site. | 2.4% | — |
| CVE-2004-1649 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter. NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future. | 2.4% | — |
| CVE-2024-38015 | HIGH 7.5 | microsoft windows_server_2012 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | 2.4% | — |
| CVE-2021-43882 | CRIT 9.0 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2019-0871 | MED 6.1 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique f | 2.4% | — |
| CVE-2019-0870 | MED 6.1 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique f | 2.4% | — |
| CVE-2019-0868 | MED 6.1 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique f | 2.4% | — |
| CVE-2016-6357 | HIGH 7.5 | cisco email_security_appliance A vulnerability in the configured security policies, including drop email filtering, in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass a configured drop filter by using an email with a corrupted | 2.4% | — |
| CVE-2016-1480 | HIGH 7.5 | cisco email_security_appliance A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters | 2.4% | — |
| CVE-2022-30651 | HIGH 7.8 | adobe incopy Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulne | 2.4% | — |
| CVE-2017-8707 | MED 5.3 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly | 2.4% | — |
| CVE-2017-8706 | MED 5.3 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper | 2.4% | — |
| CVE-2005-0177 | HIGH 7.8 | linux linux_kernel nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow. | 2.4% | — |
| CVE-2025-21276 | HIGH 7.5 | microsoft windows_10_1507 Windows MapUrlToZone Denial of Service Vulnerability | 2.4% | — |
| CVE-2021-34533 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Font Parsing Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-34530 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2018-0908 | MED 6.1 | microsoft identity_manager Microsoft Identity Manager 2016 SP1 allows an attacker to gain elevated privileges when it does not properly sanitize a specially crafted attribute value being displayed to a user on an affected MIM 2016 server, aka "Microsoft Identity Manager XSS Elevation of | 2.4% | — |
| CVE-2022-24097 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 2.4% | — |