58.645 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.645 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-27068 | HIGH 8.8 | microsoft visual_studio_2019 Visual Studio Remote Code Execution Vulnerability | 53.6% | — |
| CVE-2002-1143 | MED 5.0 | microsoft excel Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in | 53.6% | — |
| CVE-2023-32029 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 53.5% | — |
| CVE-2002-1254 | HIGH 7.5 | microsoft ie Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached | 53.5% | — |
| CVE-2021-23017 | HIGH 7.7 | f5 nginx A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. | 53.5% | — |
| CVE-2011-0104 | HIGH 9.3 | microsoft excel Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka " | 53.4% | — |
| CVE-2018-8021 | CRIT 9.8 | apache superset Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation. | 53.4% | — |
| CVE-2016-2211 | HIGH 7.8 | symantec advanced_threat_protection The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) fo | 53.4% | — |
| CVE-2005-1978 | HIGH 7.5 | microsoft windows_2000 COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code. | 53.4% | — |
| CVE-1999-0191 | MED 6.4 | microsoft internet_information_server IIS newdsn.exe CGI script allows remote users to overwrite files. | 53.3% | — |
| CVE-2019-0541 | HIGH 8.8 | microsoft excel_viewer A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explo | 53.2% | |
| CVE-2015-2419 | HIGH 8.8 | microsoft internet_explorer JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability." | 53.1% | |
| CVE-2006-5583 | HIGH 10.0 | microsoft windows_2003_server Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability." | 53.1% | — |
| CVE-2015-1642 | HIGH 7.8 | microsoft office Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." | 53.1% | |
| CVE-2010-0248 | HIGH 8.1 | microsoft internet_explorer Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka | 53.1% | — |
| CVE-2018-0840 | HIGH 7.5 | microsoft edge Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote cod | 53.1% | — |
| CVE-2012-2539 | HIGH 7.8 | microsoft office_compatibility_pack Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, ak | 53.0% | |
| CVE-2019-0808 | HIGH 7.8 | microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0797. | 53.0% | |
| CVE-2009-0557 | HIGH 7.8 | microsoft office Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel View | 53.0% | |
| CVE-2009-1955 | HIGH 7.5 | apache apr-util The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted | 53.0% | — |
| CVE-2021-22160 | CRIT 9.8 | apache pulsar If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an attacker to connect to Pulsar instances as | 52.9% | — |
| CVE-2024-38023 | HIGH 7.2 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 52.9% | — |
| CVE-2007-5348 | HIGH 9.3 | microsoft digital_image_suite Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewe | 52.9% | — |
| CVE-2019-10097 | HIGH 7.2 | apache http_server In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability co | 52.9% | — |
| CVE-2001-0538 | HIGH 10.0 | microsoft outlook Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page. | 52.9% | — |