56.560 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.560 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-27348 | CRIT 9.8 | apache hugegraph RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the | 99.2% | |
| CVE-2021-25646 | HIGH 8.8 | apache druid Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possibl | 99.2% | — |
| CVE-2020-11978 | HIGH 8.8 | apache airflow An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running | 99.2% | |
| CVE-2022-30333 | HIGH 7.5 | ransomware debian debian_linux RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected. | 99.1% | |
| CVE-2020-0618 | HIGH 8.8 | ransomware microsoft sql_server A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'. | 99.0% | |
| CVE-2021-21978 | CRIT 9.8 | vmware view_planner VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network acces | 99.0% | — |
| CVE-2017-3881 | CRIT 9.8 | cisco ios A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The | 99.0% | |
| CVE-2011-3192 | HIGH 7.8 | apache http_server The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited i | 98.9% | — |
| CVE-2023-36884 | HIGH 7.5 | ransomware microsoft windows_10_1507 Windows Search Remote Code Execution Vulnerability | 98.9% | |
| CVE-2020-9496 | MED 6.1 | apache ofbiz XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 | 98.9% | — |
| CVE-2012-1442 | MED 4.3 | aladdin esafe The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, F-Secure Anti-Virus 9.0.16160.0, Sophos Anti-Virus 4.61.0, | 98.9% | — |
| CVE-2017-9791 | CRIT 9.8 | apache struts The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage. | 98.9% | |
| CVE-2008-4250 | CRIT 9.8 | microsoft windows_2000 The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canoni | 98.8% | |
| CVE-2019-11477 | HIGH 7.5 | canonical ubuntu_linux Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fix | 98.7% | — |
| CVE-2024-29059 | HIGH 7.5 | microsoft .net_framework .NET Framework Information Disclosure Vulnerability | 98.6% | |
| CVE-2025-32433 | CRIT 10.0 | cisco cloud_native_broadband_network_gateway Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protoco | 98.6% | |
| CVE-2019-17558 | HIGH 7.5 | apache solr Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset | 98.6% | |
| CVE-2016-3088 | CRIT 9.8 | apache activemq The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request. | 98.5% | |
| CVE-2024-9463 | HIGH 7.5 | paloaltonetworks expedition An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys | 98.5% | |
| CVE-2003-0352 | HIGH 7.5 | microsoft windows_2000 Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms. | 98.5% | — |
| CVE-2025-0108 | CRIT 9.1 | paloaltonetworks pan-os An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain | 98.5% | |
| CVE-2017-15944 | CRIT 9.8 | paloaltonetworks pan-os Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface. | 98.3% | |
| CVE-2012-1457 | MED 4.3 | aladdin esafe The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti- | 98.3% | — |
| CVE-2023-20887 | CRIT 9.8 | vmware aria_operations_for_networks Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution. | 98.3% | |
| CVE-2024-55591 | CRIT 9.8 | ransomware fortinet fortios An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via | 98.3% |