58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-6766 | MED 5.5 | foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious | 2.7% | — |
| CVE-2019-6758 | MED 5.5 | foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fi | 2.7% | — |
| CVE-2017-6750 | HIGH 7.5 | cisco web_security_appliance A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the we | 2.7% | — |
| CVE-2023-36010 | HIGH 7.5 | microsoft malware_protection_platform Microsoft Defender Denial of Service Vulnerability | 2.7% | — |
| CVE-2022-30657 | HIGH 7.8 | adobe incopy Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi | 2.7% | — |
| CVE-2022-30655 | HIGH 7.8 | adobe incopy Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi | 2.7% | — |
| CVE-2011-0164 | HIGH 7.6 | apple itunes WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability | 2.7% | — |
| CVE-2007-0211 | HIGH 7.2 | microsoft windows_2003_server The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardw | 2.7% | — |
| CVE-2021-40452 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-34500 | MED 6.3 | microsoft windows_10 Windows Kernel Memory Information Disclosure Vulnerability | 2.7% | — |
| CVE-2010-4258 | MED 6.2 | fedoraproject fedora The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by | 2.7% | — |
| CVE-2026-34355 | HIGH 7.5 | apache http_server A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue. | 2.7% | — |
| CVE-2019-0216 | MED 4.8 | apache airflow A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. | 2.7% | — |
| CVE-2016-1365 | HIGH 8.8 | cisco application_policy_infrastructure_controller_enterprise_module The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users to execute arbitrary commands as root via a crafted upgrade parameter, aka Bug ID CSCux15507. | 2.7% | — |
| CVE-2025-59230 | HIGH 7.8 | microsoft windows_10_1507 Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 2.7% | |
| CVE-2024-38126 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.7% | — |
| CVE-2018-14609 | MED 5.5 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in __del_reloc_root() in fs/btrfs/relocation.c when mounting a crafted btrfs image, related to removing reloc rb_trees when reloc control has not been initiali | 2.7% | — |
| CVE-2022-21980 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2020-9568 | HIGH 7.8 | adobe bridge Adobe Bridge versions 10.0.1 and earlier version have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution . | 2.7% | — |
| CVE-2010-1734 | MED 4.9 | microsoft windows_2000 The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call fo | 2.7% | — |
| CVE-2022-38450 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue req | 2.7% | — |
| CVE-2020-2014 | HIGH 8.8 | paloaltonetworks pan-os An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; P | 2.7% | — |
| CVE-2008-4618 | HIGH 7.8 | linux linux_kernel The Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.27 does not properly handle a protocol violation in which a parameter has an invalid length, which allows attackers to cause a denial of service (panic) via unspecifi | 2.7% | — |
| CVE-2023-36034 | HIGH 7.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-22042 | MED 6.5 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 2.7% | — |