IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.650 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2024-36971 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first 2.7%
CVE-2022-20719 MED 5.5 cisco ios_xe Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system 2.7% —
CVE-2019-16714 HIGH 7.5 canonical ubuntu_linux In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized. 2.7% —
CVE-2012-2100 HIGH 7.1 linux linux_kernel The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 3.2.2, on the x86 platform and unspecified other platforms, allows user-assisted remote attackers to trigger inconsistent filesystem-groups data and possibly cause a denial of servi 2.7% —
CVE-2011-2444 MED 4.3 adobe flash_player Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to a "univer 2.7% —
CVE-2009-0522 MED 4.3 adobe air Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the "mouse pointer display," related to a "Clickjacking attack." 2.7% —
CVE-2020-7868 CRIT 9.6 helpu helpu A remote code execution vulnerability exists in helpUS(remote administration tool) due to improper validation of parameter of ShellExecutionExA function used for login. 2.7% —
CVE-2016-6452 CRIT 9.8 cisco prime_home A vulnerability in the web-based graphical user interface (GUI) of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. Cisco Prime Home versions 5.1.1.6 and ear 2.7% —
CVE-2021-24071 MED 5.3 microsoft sharepoint_enterprise_server Microsoft SharePoint Information Disclosure Vulnerability 2.7% —
CVE-2010-4008 MED 4.3 apache openoffice libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a deni 2.7% —
CVE-2026-45659 HIGH 8.8 ransomware microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 2.7%
CVE-2021-1618 MED 6.5 cisco intersight_virtual_appliance Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnerabilities are due to i 2.7% —
CVE-2018-16871 HIGH 7.5 linux linux_kernel A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can 2.7% —
CVE-2017-7165 HIGH 8.8 apple icloud An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affecte 2.7% —
CVE-2022-22041 MED 6.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 2.7% —
CVE-2021-28475 HIGH 7.8 microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability 2.7% —
CVE-2021-28473 HIGH 7.8 microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability 2.7% —
CVE-2021-28469 HIGH 7.8 microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability 2.7% —
CVE-2021-28457 HIGH 7.8 microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability 2.7% —
CVE-2018-19451 HIGH 7.8 foxitsoftware foxit_pdf_sdk_activex A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when using the Open File action on a Field. An attacker can leverage this to gain remote code execution. 2.7% —
CVE-2008-2528 HIGH 10.0 citrix access_gateway Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "access to network resources" via unspecified vectors. 2.7% —
CVE-2024-21404 HIGH 7.5 microsoft asp.net_core .NET Denial of Service Vulnerability 2.7% —
CVE-2021-33780 HIGH 8.8 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 2.7% —
CVE-2011-0155 HIGH 7.6 apple itunes WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability 2.7% —
CVE-2011-0152 HIGH 7.6 apple itunes WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability 2.7% —