56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.569 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-9513 | HIGH 7.5 | apache traffic_server Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority | 81.6% | — |
| CVE-2019-0752 | HIGH 7.5 | ransomware microsoft internet_explorer A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0753, CVE-2019-0862. | 81.6% | |
| CVE-2009-1185 | HIGH 7.2 | canonical ubuntu_linux udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. | 81.5% | — |
| CVE-2007-0774 | HIGH 7.5 | apache tomcat_jk_web_server_connector Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code v | 81.5% | — |
| CVE-2019-10092 | MED 6.1 | apache http_server In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploit | 81.5% | — |
| CVE-2017-11826 | HIGH 7.8 | microsoft office_compatibility_pack Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code executio | 81.5% | |
| CVE-2023-32031 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 81.5% | — |
| CVE-2003-0344 | HIGH 7.5 | microsoft ie Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page. | 81.3% | — |
| CVE-2003-0822 | HIGH 7.5 | microsoft frontpage_server_extensions Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request. | 81.3% | — |
| CVE-2023-36777 | MED 5.7 | microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability | 81.2% | — |
| CVE-2003-0719 | HIGH 7.5 | microsoft netmeeting Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attac | 81.2% | — |
| CVE-2011-5034 | HIGH 7.8 | apache geronimo Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. | 81.2% | — |
| CVE-2021-4104 | HIGH 7.5 | apache log4j JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to per | 81.1% | — |
| CVE-2023-36745 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 81.1% | — |
| CVE-2021-31955 | MED 5.5 | microsoft windows_10_1809 Windows Kernel Information Disclosure Vulnerability | 81.1% | |
| CVE-2021-30128 | CRIT 9.8 | apache ofbiz Apache OFBiz has unsafe deserialization prior to 17.12.07 version | 81.1% | — |
| CVE-2013-4212 | MED 6.8 | apache roller Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter, as demonstrated by the pageTitle parameter in the !getPageTitle sub-URL to rol | 81.1% | — |
| CVE-2003-0812 | HIGH 7.5 | microsoft windows_2000 Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the | 81.0% | — |
| CVE-2022-34169 | HIGH 7.5 | apache xalan-java The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are rec | 81.0% | — |
| CVE-2021-36749 | MED 6.5 | apache druid In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of th | 81.0% | — |
| CVE-2022-31704 | CRIT 9.8 | vmware vrealize_log_insight The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution. | 81.0% | — |
| CVE-2017-0262 | HIGH 7.8 | microsoft office Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and | 81.0% | |
| CVE-2016-7255 | HIGH 7.8 | microsoft windows_10_1507 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileg | 81.0% | |
| CVE-2021-38540 | CRIT 9.8 | apache airflow The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclos | 80.9% | — |
| CVE-2025-21298 | CRIT 9.8 | microsoft windows_10_1507 Windows OLE Remote Code Execution Vulnerability | 80.9% | — |