58.586 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.586 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-32031 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 81.5% | — |
| CVE-2017-0290 | HIGH 7.8 | microsoft forefront_security The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a | 81.4% | — |
| CVE-2010-2883 | HIGH 7.3 | adobe acrobat Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a l | 81.4% | |
| CVE-2003-0344 | HIGH 7.5 | microsoft ie Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page. | 81.3% | — |
| CVE-2021-30128 | CRIT 9.8 | apache ofbiz Apache OFBiz has unsafe deserialization prior to 17.12.07 version | 81.2% | — |
| CVE-2003-0719 | HIGH 7.5 | microsoft netmeeting Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attac | 81.2% | — |
| CVE-2017-11826 | HIGH 7.8 | microsoft office_compatibility_pack Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code executio | 81.2% | |
| CVE-2021-31955 | MED 5.5 | microsoft windows_10_1809 Windows Kernel Information Disclosure Vulnerability | 81.1% | |
| CVE-2013-4212 | MED 6.8 | apache roller Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter, as demonstrated by the pageTitle parameter in the !getPageTitle sub-URL to rol | 81.1% | — |
| CVE-2022-34169 | HIGH 7.5 | apache xalan-java The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are rec | 81.0% | — |
| CVE-2022-31704 | CRIT 9.8 | vmware vrealize_log_insight The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution. | 81.0% | — |
| CVE-2017-0262 | HIGH 7.8 | microsoft office Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and | 81.0% | |
| CVE-2016-7255 | HIGH 7.8 | ransomware microsoft windows_10_1507 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileg | 81.0% | |
| CVE-2021-38540 | CRIT 9.8 | apache airflow The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclos | 80.9% | — |
| CVE-2025-21298 | CRIT 9.8 | microsoft windows_10_1507 Windows OLE Remote Code Execution Vulnerability | 80.9% | — |
| CVE-2024-43468 | CRIT 9.8 | microsoft configuration_manager_2403 Microsoft Configuration Manager Remote Code Execution Vulnerability | 80.9% | |
| CVE-2023-24488 | MED 6.1 | citrix application_delivery_controller Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting | 80.9% | — |
| CVE-2021-36749 | MED 6.5 | apache druid In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of th | 80.9% | — |
| CVE-2023-50164 | CRIT 9.8 | apache struts An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or S | 80.8% | — |
| CVE-2018-0758 | HIGH 7.5 | microsoft chakracore Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corrupti | 80.8% | — |
| CVE-2021-26411 | HIGH 8.8 | ransomware microsoft edge Internet Explorer Memory Corruption Vulnerability | 80.8% | |
| CVE-2007-6203 | MED 4.3 | apache http_server Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client | 80.7% | — |
| CVE-2016-6433 | HIGH 8.8 | cisco secure_firewall_management_center The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872. | 80.7% | — |
| CVE-2024-20419 | CRIT 10.0 | cisco smart_software_manager_on-prem A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper impl | 80.6% | — |
| CVE-2021-4104 | HIGH 7.5 | apache log4j JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to per | 80.6% | — |