56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.569 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1429 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428. | 72.6% | |
| CVE-2017-6316 | CRIT 9.8 | citrix netscaler_sd-wan Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID. | 72.6% | |
| CVE-2000-0945 | HIGH 10.0 | cisco catalyst_3500_xl The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory. | 72.6% | — |
| CVE-2004-0899 | MED 5.0 | microsoft windows_nt The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a | 72.6% | — |
| CVE-2008-6505 | MED 5.0 | apache struts Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0. | 72.5% | — |
| CVE-2003-0001 | MED 5.0 | freebsd freebsd Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak. | 72.5% | — |
| CVE-2013-5331 | HIGH 9.3 | adobe air Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote | 72.5% | — |
| CVE-2021-1472 | MED 5.3 | cisco rv160_firmware Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these | 72.5% | — |
| CVE-2022-20699 | CRIT 10.0 | cisco rv340_firmware Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot | 72.5% | |
| CVE-2020-11991 | HIGH 7.5 | apache cocoon When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system. | 72.5% | — |
| CVE-1999-0256 | HIGH 7.5 | jgaa warftpd Buffer overflow in War FTP allows remote execution of commands. | 72.4% | — |
| CVE-2018-0824 | HIGH 8.8 | microsoft windows_10_1507 A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1 | 72.4% | |
| CVE-2004-1134 | HIGH 10.0 | microsoft w3who.dll Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long query string. | 72.3% | — |
| CVE-2021-21345 | MED 5.8 | apache activemq XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed inpu | 72.3% | — |
| CVE-2014-0307 | HIGH 9.3 | microsoft internet_explorer Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a certain sequence of manipulations of a TextRange element, aka "Internet Explorer Memory Corru | 72.2% | — |
| CVE-2017-8740 | HIGH 7.5 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerabilit | 72.2% | — |
| CVE-2017-8729 | HIGH 7.5 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerabilit | 72.2% | — |
| CVE-2006-7196 | MED 4.3 | apache tomcat Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time | 72.2% | — |
| CVE-2024-20697 | HIGH 7.3 | microsoft windows_11_22h2 Windows libarchive Remote Code Execution Vulnerability | 72.2% | — |
| CVE-2026-21509 | HIGH 7.8 | microsoft 365_apps Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. | 72.2% | |
| CVE-2017-8636 | HIGH 7.5 | microsoft edge Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the | 72.1% | — |
| CVE-2021-42278 | HIGH 7.5 | ransomware microsoft windows_server_2004 Active Directory Domain Services Elevation of Privilege Vulnerability | 72.0% | |
| CVE-2017-8540 | HIGH 7.8 | microsoft endpoint_protection The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a | 72.0% | |
| CVE-2010-2263 | MED 5.0 | f5 nginx nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI. | 71.9% | — |
| CVE-2007-2815 | HIGH 10.0 | microsoft internet_information_services The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web | 71.9% | — |