58.586 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.586 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-7285 | CRIT 9.8 | apache activemq Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. | 84.4% | — |
| CVE-2014-0556 | HIGH 10.0 | adobe adobe_air Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before | 84.3% | — |
| CVE-2024-38077 | CRIT 9.8 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 84.2% | — |
| CVE-2024-38112 | HIGH 7.5 | microsoft windows_10_1507 Windows MSHTML Platform Spoofing Vulnerability | 84.2% | |
| CVE-2017-0213 | HIGH 7.3 | ransomware microsoft windows_10_1507 Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerabi | 84.1% | |
| CVE-2024-43451 | MED 6.5 | microsoft windows_10_1507 NTLM Hash Disclosure Spoofing Vulnerability | 84.1% | |
| CVE-2009-3129 | HIGH 7.8 | microsoft excel Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint | 84.0% | |
| CVE-2024-30044 | HIGH 7.2 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 84.0% | — |
| CVE-2023-29325 | HIGH 8.1 | microsoft windows_10_1507 Windows OLE Remote Code Execution Vulnerability | 83.9% | — |
| CVE-2020-3161 | CRIT 9.8 | cisco 8831_firmware A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to | 83.9% | |
| CVE-2021-38294 | CRIT 9.8 | apache storm A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentic | 83.8% | — |
| CVE-2019-1620 | CRIT 9.8 | cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to upload arbitrary files on an affected device. The vulnerability is due to incorrect permission settings in affe | 83.8% | — |
| CVE-2023-50386 | HIGH 8.8 | apache solr Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 | 83.7% | — |
| CVE-2024-49113 | HIGH 7.5 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | 83.6% | — |
| CVE-2019-0193 | HIGH 7.2 | apache solr In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen | 83.5% | |
| CVE-2016-5195 | HIGH 7.0 | canonical ubuntu_linux Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016 | 83.5% | |
| CVE-2012-1889 | HIGH 8.8 | microsoft xml_core_services Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. | 83.5% | |
| CVE-2022-26923 | HIGH 8.8 | microsoft windows_10_1507 Active Directory Domain Services Elevation of Privilege Vulnerability | 83.5% | |
| CVE-2005-1790 | LOW 2.6 | microsoft internet_explorer Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched | 83.5% | — |
| CVE-2023-36847 | MED 5.3 | juniper junos A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php | 83.5% | |
| CVE-2019-9512 | HIGH 7.5 | apache traffic_server Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is que | 83.4% | — |
| CVE-2024-21762 | CRIT 9.8 | ransomware fortinet fortios A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0 | 83.4% | |
| CVE-2019-1935 | CRIT 9.8 | cisco integrated_management_controller_supervisor A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account | 83.4% | — |
| CVE-2009-3733 | MED 5.0 | vmware esx Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors. | 83.4% | — |
| CVE-2009-3953 | HIGH 8.8 | adobe acrobat The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclarat | 83.2% |