56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.959 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-41973 | MED 6.5 | apache mina In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update M | 4.7% | — |
| CVE-2011-0962 | MED 4.3 | cisco unified_operations_manager Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Device Center in Cisco Unified Operations Manager (CUOM) before 8.6 allows remote attackers to inject arbitrary web script or HTML via the tag | 4.7% | — |
| CVE-2022-37967 | HIGH 7.2 | fedoraproject fedora Windows Kerberos Elevation of Privilege Vulnerability | 4.6% | — |
| CVE-2021-41368 | MED 6.1 | microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability | 4.6% | — |
| CVE-2019-6728 | MED 6.5 | foxitsoftware phantompdf This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The sp | 4.6% | — |
| CVE-2020-3258 | CRIT 9.8 | cisco ios Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker or an authenticated, local atta | 4.6% | — |
| CVE-2011-2732 | MED 4.3 | vmware springsource_spring_security CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the spring-security-red | 4.6% | — |
| CVE-2020-1961 | CRIT 9.8 | apache syncope Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (RCE) was discovered. | 4.6% | — |
| CVE-2015-5092 | MED 5.0 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access | 4.6% | — |
| CVE-2015-5089 | MED 5.0 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access | 4.6% | — |
| CVE-2015-5088 | MED 5.0 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access | 4.6% | — |
| CVE-2015-4450 | MED 5.0 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access | 4.6% | — |
| CVE-2015-4449 | MED 5.0 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access | 4.6% | — |
| CVE-2014-8450 | MED 5.0 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access | 4.6% | — |
| CVE-2019-1461 | MED 6.5 | microsoft office A denial of service vulnerability exists in Microsoft Word software when the software fails to properly handle objects in memory, aka 'Microsoft Word Denial of Service Vulnerability'. | 4.6% | — |
| CVE-2021-36965 | HIGH 8.8 | microsoft windows_10 Windows WLAN AutoConfig Service Remote Code Execution Vulnerability | 4.6% | — |
| CVE-2020-1502 | MED 5.5 | microsoft 365_apps An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, a | 4.6% | — |
| CVE-2020-1497 | MED 5.5 | microsoft 365_apps An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, | 4.6% | — |
| CVE-2019-1845 | HIGH 8.6 | cisco telepresence_video_communication_server A vulnerability in the authentication service of the Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, Cisco TelePresence Video Communication Server (VCS), and Cisco Expressway Series could allow an unauthenticated, remote att | 4.6% | — |
| CVE-2018-0420 | MED 6.5 | cisco wireless_lan_controller_software A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an authenticated, remote attacker to view sensitive information. The issue is due to improper sanitization of user-supplied input in HTTP request parameters that d | 4.6% | — |
| CVE-2013-1662 | MED 6.9 | vmware player vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen library | 4.6% | — |
| CVE-2005-0449 | HIGH 7.1 | linux linux_kernel The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function. | 4.6% | — |
| CVE-2018-17679 | HIGH 8.8 | foxitsoftware phantompdf This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 4.6% | — |
| CVE-2012-4655 | HIGH 9.3 | cisco secure_desktop The WebLaunch feature in Cisco Secure Desktop before 3.6.6020 does not properly validate binaries that are received by the downloader process, which allows remote attackers to execute arbitrary code via vectors involving (1) ActiveX or (2) Java components, aka | 4.6% | — |
| CVE-2012-6392 | HIGH 10.0 | cisco prime_lan_management_solution Cisco Prime LAN Management Solution (LMS) 4.1 through 4.2.2 on Linux does not properly validate authentication and authorization requests in TCP sessions, which allows remote attackers to execute arbitrary commands via a crafted session, aka Bug ID CSCuc79779. | 4.6% | — |