56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.793 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-21123 | MED 6.5 | google chrome Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | 10.9% | — |
| CVE-2018-5511 | HIGH 7.2 | f5 big-ip_access_policy_manager On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced. | 10.9% | — |
| CVE-2015-5175 | HIGH 7.5 | apache cxf_fediz Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service. | 10.9% | — |
| CVE-2018-1283 | MED 5.3 | apache http_server In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable | 10.9% | — |
| CVE-2007-3406 | MED 4.3 | microsoft internet_explorer Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attackers to access arbitrary local files via the file: URI in the (1) src attribute of a (a) bgsound, (b) input, (c) EMBED, (d) img, or (e) script | 10.9% | — |
| CVE-2020-1458 | HIGH 7.8 | microsoft 365_apps A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files, aka 'Microsoft Office Remote Code Execution Vulnerability'. | 10.9% | — |
| CVE-2015-2532 | MED 4.3 | microsoft lync_server Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Lync Server XSS Information Disclosure Vulnerability." | 10.9% | — |
| CVE-2015-2531 | MED 4.3 | microsoft lync_server Cross-site scripting (XSS) vulnerability in the jQuery engine in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype for Business Server and Lync Server XSS | 10.9% | — |
| CVE-2024-21371 | HIGH 7.0 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 10.9% | — |
| CVE-2006-1304 | HIGH 9.3 | microsoft excel Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation." | 10.9% | — |
| CVE-2004-2291 | HIGH 7.5 | microsoft ie Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objects and a shortcut (link) to execute the target script. | 10.9% | — |
| CVE-2003-0619 | MED 5.0 | linux linux_kernel Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call. | 10.9% | — |
| CVE-2019-17566 | HIGH 7.5 | apache batik Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary | 10.9% | — |
| CVE-2018-4314 | HIGH 8.8 | apple icloud A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7. | 10.9% | — |
| CVE-2012-0022 | MED 5.0 | apache tomcat Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and param | 10.9% | — |
| CVE-2007-3109 | MED 6.4 | microsoft frontpage The CERN Image Map Dispatcher (htimage.exe) in Microsoft FrontPage allows remote attackers to determine the existence, and possibly partial contents, of arbitrary files under the web root via a relative pathname in the PATH_INFO. | 10.9% | — |
| CVE-2007-3341 | HIGH 10.0 | microsoft internet_explorer Unspecified vulnerability in the FTP implementation in Microsoft Internet Explorer allows remote attackers to "see a valid memory address" via unspecified vectors, a different issue than CVE-2007-0217. | 10.9% | — |
| CVE-2023-23376 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 10.9% | |
| CVE-2018-11780 | CRIT 9.8 | apache spamassassin A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2. | 10.9% | — |
| CVE-2019-14439 | HIGH 7.5 | apache drill A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in t | 10.8% | — |
| CVE-2017-0279 | HIGH 7.0 | microsoft windows_10 The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacke | 10.8% | — |
| CVE-2017-0278 | HIGH 7.0 | microsoft windows_10 The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacke | 10.8% | — |
| CVE-2017-0277 | HIGH 7.0 | microsoft windows_10 The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacke | 10.8% | — |
| CVE-2000-1105 | MED 4.3 | microsoft indexing_service The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled. | 10.8% | — |
| CVE-2020-0905 | HIGH 8.0 | microsoft dynamics_365_business_central An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. | 10.8% | — |