56.775 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.775 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-5052 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | 12.5% | — |
| CVE-2013-5051 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | 12.5% | — |
| CVE-2013-5049 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | 12.5% | — |
| CVE-2013-5047 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013 | 12.5% | — |
| CVE-2012-5672 | MED 4.3 | microsoft excel Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file with bat | 12.5% | — |
| CVE-2008-5555 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain attacks, | 12.5% | — |
| CVE-2000-1003 | LOW 2.6 | microsoft windows_95 NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sharing service to return an unknown driver type, which causes the client to crash. | 12.5% | — |
| CVE-2023-36049 | HIGH 7.6 | microsoft .net .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | 12.5% | — |
| CVE-2006-3877 | HIGH 9.3 | microsoft access Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than C | 12.5% | — |
| CVE-2006-7029 | MED 5.0 | microsoft internet_explorer Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a frameset with only one frame that calls resizeTo with certain arguments. NOTE: this issue might be related to CVE-2006-3637. | 12.5% | — |
| CVE-2018-0956 | HIGH 7.5 | microsoft windows_10 A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Ser | 12.5% | — |
| CVE-2024-37080 | CRIT 9.8 | vmware vcenter_server vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remo | 12.5% | — |
| CVE-2019-1291 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-0788, CVE-2019-129 | 12.5% | — |
| CVE-2019-1290 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-0788, CVE-2019-129 | 12.5% | — |
| CVE-2019-0788 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-1290, CVE-2019-129 | 12.5% | — |
| CVE-2022-20775 | HIGH 7.8 | cisco catalyst_sd-wan_manager A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulner | 12.5% | |
| CVE-2022-27786 | HIGH 7.8 | adobe acrobat Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of fonts that could result in arbitrary code execution in the context of the curre | 12.5% | — |
| CVE-2009-3613 | HIGH 7.8 | linux linux_kernel The swiotlb functionality in the r8169 driver in drivers/net/r8169.c in the Linux kernel before 2.6.27.22 allows remote attackers to cause a denial of service (IOMMU space exhaustion and system crash) by using jumbo frames for a large amount of network traffic | 12.5% | — |
| CVE-2002-1592 | MED 5.0 | apache http_server The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information. | 12.5% | — |
| CVE-1999-0489 | HIGH 10.0 | microsoft windows_nt MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013. | 12.4% | — |
| CVE-2019-1406 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | 12.4% | — |
| CVE-2015-2402 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability." | 12.4% | — |
| CVE-2010-0437 | HIGH 7.8 | linux linux_kernel The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of serv | 12.4% | — |
| CVE-2018-8569 | HIGH 7.8 | microsoft yammer A remote code execution vulnerability exists in the Yammer desktop application due to the loading of arbitrary content, aka "Yammer Desktop Application Remote Code Execution Vulnerability." This affects Yammer Desktop App. | 12.4% | — |
| CVE-2005-4844 | HIGH 7.1 | microsoft internet_explorer The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer. | 12.4% | — |