IT
58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.639 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2021-28600 MED 5.5 adobe after_effects Adobe After Effects version 18.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of th 2.4% —
CVE-2020-4854 CRIT 9.8 ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-For 2.4% —
CVE-2017-5044 MED 6.3 debian debian_linux Heap buffer overflow in filter processing in Skia in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. 2.4% —
CVE-2012-1517 HIGH 9.0 vmware esx The VMX process in VMware ESXi 4.1 and ESX 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrite and process crash) or possibly execute arbitrary code on the host OS via vectors involving function 2.4% —
CVE-2022-29139 HIGH 8.8 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 2.4% —
CVE-2023-36720 HIGH 7.5 microsoft windows_10_1607 Windows Mixed Reality Developer Tools Denial of Service Vulnerability 2.4% —
CVE-2023-36703 HIGH 7.5 microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability 2.4% —
CVE-2021-26606 CRIT 9.8 dreamsecurity magicline4nx.exe A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certificate. An attacker could exploit this vulnerability by sending a crafted HTTP re 2.4% —
CVE-2021-24088 HIGH 8.8 microsoft windows_10 Windows Local Spooler Remote Code Execution Vulnerability 2.4% —
CVE-2020-17162 HIGH 8.8 microsoft windows_10 Microsoft Windows Security Feature Bypass Vulnerability 2.4% —
CVE-2016-7476 HIGH 7.5 f5 big-ip_access_policy_manager The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, APM, ASM, GTM, Link Controller, PEM, PSM, and WebSafe 11.6.0 before 11.6.0 HF6, 11.5.0 before 11.5.3 HF2, and 11.3.0 before 11.4.1 HF10 may suffer from a memory leak while handling certain ty 2.4% —
CVE-2021-31943 HIGH 7.8 microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability 2.4% —
CVE-2020-36277 HIGH 7.5 debian debian_linux Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c. 2.4% —
CVE-2020-25645 HIGH 7.5 canonical ubuntu_linux A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints t 2.4% —
CVE-2019-1170 HIGH 7.9 microsoft windows_10 An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox escape. An attacker who successfully exploited the vulnerability could use the sandbox escape to elevate privileges on an affected system. To 2.4% —
CVE-2004-1759 MED 5.0 cisco call_manager Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning. 2.4% —
CVE-2022-41704 HIGH 7.5 apache batik A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16. 2.4% —
CVE-2022-22028 MED 5.9 microsoft windows_server_2008 Windows Network File System Information Disclosure Vulnerability 2.4% —
CVE-2022-21919 HIGH 7.0 microsoft windows_10_1507 Windows User Profile Service Elevation of Privilege Vulnerability 2.4%
CVE-2004-0077 HIGH 7.2 linux linux_kernel The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to 2.4% —
CVE-2019-0635 MED 6.2 microsoft windows_10 An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'. 2.4% —
CVE-2015-6301 MED 5.0 cisco asr_9001 The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun72171. 2.4% —
CVE-2015-6297 MED 5.0 cisco ios_xr The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun36525. 2.4% —
CVE-2018-8168 MED 5.4 microsoft sharepoint_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft 2.4% —
CVE-2015-2453 MED 4.7 microsoft windows_10 The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive informat 2.4% —