58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-29148 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2021-43908 | MED 4.3 | microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability | 2.8% | — |
| CVE-2021-32824 | CRIT 9.8 | apache dubbo Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to access a Telnet Hand | 2.8% | — |
| CVE-2023-21744 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2018-6342 | CRIT 9.8 | facebook react-dev-utils react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The input to that command was not properly sanitized, allowing an attacker who can make a network request to the serv | 2.8% | — |
| CVE-2018-14242 | HIGH 8.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 2.8% | — |
| CVE-2018-11623 | HIGH 8.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 2.8% | — |
| CVE-2000-1088 | MED 4.6 | microsoft data_engine The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows | 2.8% | — |
| CVE-2023-36003 | MED 6.7 | microsoft windows_10_1507 XAML Diagnostics Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2022-24515 | MED 6.5 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2008-5536 | HIGH 9.3 | pandasecurity panda_antivirus Panda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .tx | 2.8% | — |
| CVE-2019-19070 | HIGH 7.5 | fedoraproject fedora A memory leak in the spi_gpio_probe() function in drivers/spi/spi-gpio.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering devm_add_action_or_reset() failures, aka CID-d3b0ffa1d75d. NOTE: third | 2.8% | — |
| CVE-2018-3992 | HIGH 8.8 | foxitsoftware phantompdf An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.2.0.9297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code exe | 2.8% | — |
| CVE-2017-12632 | HIGH 7.5 | apache nifi A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x relea | 2.8% | — |
| CVE-2004-2176 | MED 4.6 | microsoft windows_xp The Internet Connection Firewall (ICF) in Microsoft Windows XP SP2 is configured by default to trust sessmgr.exe, which allows local users to use sessmgr.exe to create a local listening port that bypasses the ICF access controls. | 2.8% | — |
| CVE-2022-28274 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this | 2.8% | — |
| CVE-2018-5314 | HIGH 7.5 | citrix netscaler_application_delivery_controller Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 500 | 2.8% | — |
| CVE-2006-1624 | HIGH 7.8 | linux linux_kernel The default configuration of syslogd in the Linux sysklogd package does not enable the -x (disable name lookups) option, which allows remote attackers to cause a denial of service (traffic amplification) via messages with spoofed source IP addresses. | 2.8% | — |
| CVE-2022-26779 | HIGH 7.5 | apache cloudstack Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that | 2.9% | — |
| CVE-2012-3552 | MED 5.9 | linux linux_kernel Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system crash) by sending packets to an application that sets socket options during the handling of network tra | 2.9% | — |
| CVE-2014-3358 | HIGH 7.8 | cisco ios Memory leak in Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allows remote attackers to cause a denial of service (memory consumption, and interface queue wedge | 2.9% | — |
| CVE-2014-3357 | HIGH 7.8 | cisco ios Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allow remote attackers to cause a denial of service (device reload) via malformed mDNS packets, aka Bug ID CSCul908 | 2.9% | — |
| CVE-2017-5640 | CRIT 9.8 | apache impala It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to skip authentication checks when Kerberos is enabled (but TLS is not). If the malicious server responds with 'COMPL | 2.9% | — |
| CVE-2020-17055 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability | 2.9% | — |
| CVE-2020-17044 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability | 2.9% | — |