58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-54098 | HIGH 7.8 | microsoft windows_10_1507 Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 2.8% | — |
| CVE-2014-0664 | MED 6.8 | cisco unity_connection The server in Cisco Unity Connection allows remote authenticated users to cause a denial of service (CPU consumption) via unspecified IMAP commands, aka Bug ID CSCul49976. | 2.8% | — |
| CVE-2000-1087 | MED 4.6 | microsoft data_engine The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allow | 2.8% | — |
| CVE-2000-1086 | MED 4.6 | microsoft data_engine The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allow | 2.8% | — |
| CVE-2000-1084 | MED 4.6 | microsoft data_engine The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an att | 2.8% | — |
| CVE-2000-1082 | MED 4.6 | microsoft data_engine The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an at | 2.8% | — |
| CVE-2024-26197 | MED 6.5 | microsoft windows_server_2012 Windows Standards-Based Storage Management Service Denial of Service Vulnerability | 2.8% | — |
| CVE-2023-36028 | CRIT 9.8 | microsoft windows_10_1507 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2021-28555 | MED 6.5 | adobe acrobat Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to get access to | 2.8% | — |
| CVE-2022-23192 | MED 5.5 | adobe illustrator Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex | 2.8% | — |
| CVE-2026-44825 | HIGH 8.1 | apache solr Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials instal | 2.8% | — |
| CVE-2022-34227 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of | 2.8% | — |
| CVE-2020-0890 | MED 6.5 | microsoft windows_10 <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.</p> <p>To exploit the vulnerability, an attacker who already has a privileged accoun | 2.8% | — |
| CVE-2018-0330 | HIGH 8.8 | cisco nx-os A vulnerability in the NX-API management application programming interface (API) in devices running, or based on, Cisco NX-OS Software could allow an authenticated, remote attacker to execute commands with elevated privileges. The vulnerability is due to a fai | 2.8% | — |
| CVE-2012-1821 | MED 5.0 | symantec endpoint_protection The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.700x on Windows Server 2003 allows remote attackers to cause a denial of service (web-server outage, or daemon crash or hang) via a flood | 2.8% | — |
| CVE-2015-4262 | HIGH 10.0 | cisco unified_meetingplace_web_conferencing The password-change feature in Cisco Unified MeetingPlace Web Conferencing before 8.5(5) MR3 and 8.6 before 8.6(2) does not check the session ID or require entry of the current password, which allows remote attackers to reset arbitrary passwords via a crafted | 2.8% | — |
| CVE-2021-27576 | HIGH 7.5 | apache openmeetings If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0 | 2.8% | — |
| CVE-2008-2735 | HIGH 7.1 | cisco adaptive_security_appliance_5500 The HTTP server in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0 before 8.0(3)15 and 8.1 before 8.1(1)5, when configured as a clientless SSL VPN endpoint, does not properly process URIs, which allows remote attackers to cause a denial of service (de | 2.8% | — |
| CVE-2008-2734 | HIGH 7.1 | cisco adaptive_security_appliance_5500 Memory leak in the crypto functionality in Cisco Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a clientless SSL VPN endpoint, allows remote attackers to cause a denial of serv | 2.8% | — |
| CVE-2017-1000405 | HIGH 7.0 | linux linux_kernel The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside the THP implementation. touch_pmd() can be reached by get_user_pages(). In such case, the pmd will become dirty. This scenario breaks the n | 2.8% | — |
| CVE-2021-26867 | CRIT 9.9 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2017-6609 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the IPsec code of Cisco ASA Software could allow an authenticated, remote attacker to cause a reload of the affected system. The vulnerability is due to improper parsing of malformed IPsec packets. An attacker could exploit this vulnerabilit | 2.8% | — |
| CVE-2018-0743 | HIGH 7.0 | microsoft windows_10 Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Subsystem for Linux Elevation of Privile | 2.8% | — |
| CVE-2010-0571 | HIGH 8.5 | cisco digital_media_manager Unspecified vulnerability in Cisco Digital Media Manager (DMM) 5.0.x and 5.1.x allows remote authenticated users to gain privileges via unknown vectors, and consequently execute arbitrary code via a crafted web application, aka Bug ID CSCtc46008. | 2.8% | — |
| CVE-2023-38243 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such a | 2.8% | — |