58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-53779 | HIGH 7.2 | microsoft windows_server_2025 Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network. | 2.7% | — |
| CVE-2021-37149 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. | 2.7% | — |
| CVE-2021-37148 | HIGH 7.5 | apache traffic_server Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1. | 2.7% | — |
| CVE-2020-0878 | MED 4.2 | ransomware microsoft chakracore <p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker | 2.7% | |
| CVE-2019-0757 | MED 6.5 | microsoft .net_core_sdk A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'. | 2.7% | — |
| CVE-2018-8584 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 | 2.7% | — |
| CVE-2015-4444 | MED 5.0 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to cause a denial of servi | 2.7% | — |
| CVE-2015-4443 | MED 5.0 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to cause a denial of servi | 2.7% | — |
| CVE-2010-0233 | HIGH 7.2 | microsoft windows_2000 Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vuln | 2.7% | — |
| CVE-2010-0190 | MED 4.3 | adobe acrobat Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2.7% | — |
| CVE-2005-4886 | HIGH 7.8 | linux linux_kernel The selinux_parse_skb_ipv6 function in security/selinux/hooks.c in the Linux kernel before 2.6.12-rc4 allows remote attackers to cause a denial of service (OOPS) via vectors associated with an incorrect call to the ipv6_skip_exthdr function. | 2.7% | — |
| CVE-1999-0975 | MED 4.6 | microsoft windows_95 The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed. | 2.7% | — |
| CVE-2026-9256 | HIGH 8.1 | debian debian_linux NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/( | 2.7% | — |
| CVE-2020-17040 | MED 6.5 | microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability | 2.7% | — |
| CVE-2020-13872 | HIGH 8.8 | royalapps royal_ts Royal TS before 5 has a 0.0.0.0 listener, which makes it easier for attackers to bypass tunnel authentication via a brute-force approach. | 2.7% | — |
| CVE-2017-2343 | CRIT 10.0 | juniper junos The Integrated User Firewall (UserFW) feature was introduced in Junos OS version 12.1X47-D10 on the Juniper SRX Series devices to provide simple integration of user profiles on top of the existing firewall polices. As part of an internal security review of the | 2.7% | — |
| CVE-2005-0597 | MED 5.0 | cisco application_and_content_networking_software Cisco devices running Application and Content Networking System (ACNS) 5.0 before 5.0.17.6 and 5.1 before 5.1.11.6 allow remote attackers to cause a denial of service (process restart) via a "crafted TCP connection." | 2.7% | — |
| CVE-2016-7560 | CRIT 9.8 | fortinet fortiwlc The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which allows remote attackers to read or write to arbitrary files via unspecified vectors. | 2.7% | — |
| CVE-2022-34734 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-34732 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-34730 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-34727 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-34726 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-24971 | HIGH 8.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 2.7% | — |
| CVE-2024-38168 | HIGH 7.5 | microsoft .net .NET and Visual Studio Denial of Service Vulnerability | 2.7% | — |