56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-16873 | MED 4.7 | microsoft xamarin.forms <p>A spoofing vulnerability manifests in Microsoft Xamarin.Forms due to the default settings on Android WebView version prior to 83.0.4103.106. This vulnerability could allow an attacker to execute arbitrary Javascript code on a target system.</p> <p>For the a | 4.0% | — |
| CVE-2021-42728 | HIGH 7.8 | adobe bridge Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a v | 4.0% | — |
| CVE-2021-30623 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30623 Use after free in Bookmarks | 4.0% | — |
| CVE-2018-8518 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 4.0% | — |
| CVE-2017-8664 | HIGH 8.8 | microsoft windows_10 Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from a privileged user on a gu | 4.0% | — |
| CVE-2017-8591 | HIGH 7.8 | microsoft windows_10 Windows Input Method Editor (IME) in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an remote code execution vulnerability when it fails to properly handle objects in memory, | 4.0% | — |
| CVE-2019-0736 | CRIT 9.8 | microsoft windows_10 A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine. To exploit the vul | 4.0% | — |
| CVE-2018-4204 | HIGH 8.8 | apple icloud An issue was discovered in certain Apple products. iOS before 11.4 is affected. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. | 4.0% | — |
| CVE-2021-39821 | HIGH 7.8 | adobe indesign Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) are affected by an out-of-bounds read vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in t | 4.0% | — |
| CVE-2020-9678 | HIGH 8.8 | adobe prelude Adobe Prelude versions 9.0 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | 4.0% | — |
| CVE-2020-3736 | HIGH 8.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 4.0% | — |
| CVE-2020-3733 | HIGH 8.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 4.0% | — |
| CVE-2020-3728 | HIGH 8.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 4.0% | — |
| CVE-2020-3726 | HIGH 8.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 4.0% | — |
| CVE-2020-3725 | HIGH 8.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 4.0% | — |
| CVE-2020-3724 | HIGH 8.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 4.0% | — |
| CVE-2020-3723 | HIGH 8.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 4.0% | — |
| CVE-2020-3721 | HIGH 8.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 4.0% | — |
| CVE-2020-3720 | HIGH 8.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 4.0% | — |
| CVE-2015-5080 | HIGH 9.0 | citrix netscaler_application_delivery_controller_firmware The Management Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before 10.1.132.8, 10.5 before Build 56.15, and 10.5.e before Build 56.1505.e allows remote authenticated users to execute arbitrary shell commands vi | 4.0% | — |
| CVE-2019-0683 | MED 5.9 | microsoft windows_7 An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privi | 4.0% | — |
| CVE-2021-1141 | CRIT 9.8 | cisco smart_software_manager_satellite Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details | 4.0% | — |
| CVE-2021-1139 | CRIT 9.8 | cisco smart_software_manager_satellite Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details | 4.0% | — |
| CVE-2018-0418 | HIGH 8.6 | cisco ios_xr A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services Router Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vuln | 4.0% | — |
| CVE-2005-2458 | MED 5.0 | linux linux_kernel inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 allows remote attackers to cause a denial of service (kernel crash) via a compressed file with "improper tables". | 4.0% | — |