56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.569 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2012-0394 | MED 6.8 | apache struts The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itsel | 74.4% | — |
| CVE-2017-8046 | CRIT 9.8 | pivotal_software spring_data_rest Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code. | 74.4% | — |
| CVE-2020-10188 | CRIT 9.8 | arista eos utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions. | 74.3% | — |
| CVE-2015-3087 | HIGH 10.0 | adobe air Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 | 74.3% | — |
| CVE-2021-40449 | HIGH 7.8 | ransomware microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 74.1% | |
| CVE-2012-0002 | HIGH 9.3 | microsoft windows_7 The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remo | 74.1% | — |
| CVE-2013-2551 | HIGH 8.8 | ransomware microsoft internet_explorer Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013 | 74.1% | |
| CVE-2013-0081 | MED 5.0 | microsoft sharepoint_foundation Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers to cause a denial of service (W3WP process hang) via a crafted URL, aka "SharePoi | 74.1% | — |
| CVE-2019-12991 | HIGH 8.8 | citrix netscaler_sd-wan Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). | 74.1% | |
| CVE-2007-2897 | HIGH 7.5 | microsoft internet_information_server Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic); and might allow attackers with physical access | 74.0% | — |
| CVE-2016-9244 | HIGH 7.5 | f5 big-ip_access_policy_manager A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session | 74.0% | — |
| CVE-2019-10098 | MED 6.1 | apache http_server In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL. | 74.0% | — |
| CVE-2018-8414 | HIGH 8.8 | microsoft windows_10_1703 A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10. | 74.0% | |
| CVE-2005-1213 | HIGH 7.5 | microsoft outlook_express Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field. | 74.0% | — |
| CVE-2020-3248 | CRIT 9.8 | cisco ucs_director Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne | 73.9% | — |
| CVE-2013-3918 | HIGH 8.8 | microsoft windows_7 The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, an | 73.9% | |
| CVE-2005-0059 | HIGH 10.0 | microsoft windows_2000 Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message. | 73.9% | — |
| CVE-2019-1458 | HIGH 7.8 | ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. | 73.9% | |
| CVE-2014-0659 | HIGH 10.0 | cisco rvs4000 The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and exe | 73.8% | — |
| CVE-2013-1814 | MED 4.0 | apache rave The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field | 73.8% | — |
| CVE-2012-0013 | HIGH 9.3 | microsoft windows_7 Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arb | 73.8% | — |
| CVE-2019-1234 | HIGH 7.5 | microsoft azure_stack A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'. | 73.7% | — |
| CVE-2018-8120 | HIGH 7.0 | ransomware microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID | 73.7% | |
| CVE-2018-5390 | HIGH 7.5 | a10networks advanced_core_operating_system Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. | 73.7% | — |
| CVE-2005-3352 | MED 4.3 | apache http_server Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps. | 73.7% | — |