56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.959 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-6393 | HIGH 7.5 | cisco ios The AAA service in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.1 through 3.18 and 16.2 allows remote attackers to cause a denial of service (device reload) via a failed SSH connection attempt that is mishandled during generation of an error- | 4.6% | — |
| CVE-2024-34750 | HIGH 7.5 | apache tomcat Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 st | 4.6% | — |
| CVE-2021-21980 | HIGH 7.5 | vmware cloud_foundation The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information. | 4.6% | — |
| CVE-2020-1256 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> <p> | 4.6% | — |
| CVE-2013-6791 | MED 4.3 | microsoft enhanced_mitigation_experience_toolkit Microsoft Enhanced Mitigation Experience Toolkit (EMET) before 4.0 uses predictable addresses for hooked functions, which makes it easier for context-dependent attackers to defeat the ASLR protection mechanism via a return-oriented programming (ROP) attack. | 4.6% | — |
| CVE-2025-60710 | HIGH 7.8 | ransomware microsoft windows_11_24h2 Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. | 4.6% | |
| CVE-2022-20702 | CRIT 10.0 | cisco rv160_firmware Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot | 4.6% | — |
| CVE-2018-4928 | HIGH 7.8 | adobe indesign Adobe InDesign versions 13.0 and below have an exploitable Memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | 4.6% | — |
| CVE-2020-17086 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 4.6% | — |
| CVE-2017-5644 | MED 5.5 | apache poi Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack. | 4.6% | — |
| CVE-2025-21269 | MED 4.3 | microsoft windows_10_1507 Windows HTML Platforms Security Feature Bypass Vulnerability | 4.6% | — |
| CVE-2018-0599 | HIGH 7.8 | microsoft windows Untrusted search path vulnerability in the installer of Visual C++ Redistributable allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 4.6% | — |
| CVE-2026-20840 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 4.6% | — |
| CVE-2014-3579 | CRIT 9.8 | apache activemq_apollo XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages. | 4.6% | — |
| CVE-2020-9493 | CRIT 9.8 | apache chainsaw A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution. | 4.6% | — |
| CVE-2020-1097 | MED 6.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.</p> <p>Th | 4.6% | — |
| CVE-2015-0249 | HIGH 7.2 | apache roller The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL). | 4.6% | — |
| CVE-2020-1449 | HIGH 7.8 | microsoft 365_apps A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, aka 'Microsoft Project Remote Code Execution Vulnerability'. | 4.6% | — |
| CVE-2010-0600 | HIGH 10.0 | cisco mediator_framework Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not properly restrict network access to an un | 4.6% | — |
| CVE-2019-8246 | CRIT 9.8 | adobe media_encoder Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | 4.6% | — |
| CVE-2014-0573 | HIGH 10.0 | adobe air Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15. | 4.6% | — |
| CVE-2004-0391 | HIGH 10.0 | cisco hosting_solution_engine Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration. | 4.6% | — |
| CVE-2014-0454 | HIGH 7.5 | canonical ubuntu_linux Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security. | 4.6% | — |
| CVE-2002-1981 | MED 5.0 | microsoft sql_server Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert setting | 4.6% | — |
| CVE-2021-31966 | HIGH 7.2 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 4.6% | — |