58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2012-4618 | HIGH 7.8 | cisco ios The SIP ALG feature in the NAT implementation in Cisco IOS 12.2, 12.4, and 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via transit IP packets, aka Bug ID CSCtn76183. | 2.7% | — |
| CVE-2011-1176 | MED 4.3 | debian debian_linux The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might al | 2.7% | — |
| CVE-2007-1215 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain "color-related parameters" in crafted images. | 2.7% | — |
| CVE-2015-1643 | HIGH 7.2 | microsoft windows_7 Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local user | 2.7% | — |
| CVE-2020-3755 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure . | 2.7% | — |
| CVE-2020-3747 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure . | 2.7% | — |
| CVE-2015-4204 | MED 6.8 | cisco cisco_ios Memory leak in Cisco IOS 12.2 in the Performance Routing Engine (PRE) module on uBR10000 devices allows remote authenticated users to cause a denial of service (memory consumption or PXF process crash) by sending docsIfMCmtsMib SNMP requests quickly, aka Bug I | 2.7% | — |
| CVE-2024-23666 | HIGH 7.5 | fortinet fortianalyzer A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and | 2.7% | — |
| CVE-2021-20557 | HIGH 7.2 | ibm security_guardium IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 199184. | 2.7% | — |
| CVE-2019-12812 | CRIT 9.8 | activesoft mybuilder MyBuilder viewer before 6.2.2019.814 allow an attacker to execute arbitrary command via specifically crafted configuration file. This can be leveraged for code execution. | 2.7% | — |
| CVE-2016-4967 | MED 6.5 | fortinet fortiwan Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to obtain sensitive information from (1) a backup of the device configuration via script/cfg_show.php or (2) PCAP files via script/system/tcpdump.php. | 2.7% | — |
| CVE-2013-6744 | HIGH 8.5 | ibm db2 The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated users to gain privileges by leveraging the CONNECT privilege and the CREATE_EXTERNAL_ROUTINE authority. | 2.7% | — |
| CVE-2024-20676 | HIGH 8.0 | microsoft azure_storage_mover Azure Storage Mover Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2023-47804 | HIGH 8.8 | apache openoffice Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject | 2.7% | — |
| CVE-2022-30172 | MED 5.5 | microsoft office_online_server Microsoft Office Information Disclosure Vulnerability | 2.7% | — |
| CVE-2021-38645 | HIGH 7.8 | microsoft azure_automation_state_configuration Open Management Infrastructure Elevation of Privilege Vulnerability | 2.7% | |
| CVE-2017-13884 | HIGH 8.8 | apple icloud An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affecte | 2.7% | — |
| CVE-2022-33639 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2006-0340 | HIGH 7.1 | cisco ios Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network | 2.7% | — |
| CVE-2022-30133 | CRIT 9.8 | microsoft windows_10 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2020-16969 | HIGH 7.1 | microsoft exchange_server <p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user.</p> <p>To exploit the | 2.7% | — |
| CVE-2021-32785 | MED 5.3 | debian debian_linux mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. When mod_auth_openidc versions prior to 2.4.9 are configured t | 2.7% | — |
| CVE-2010-0146 | MED 6.8 | cisco security_agent Directory traversal vulnerability in the Management Center for Cisco Security Agents 6.0 allows remote authenticated users to read arbitrary files via unspecified vectors. | 2.7% | — |
| CVE-2009-3294 | MED 5.0 | php php The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" string in the | 2.7% | — |
| CVE-2016-8746 | MED 5.9 | apache ranger Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true. | 2.7% | — |