IT
57.020 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

57.020 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2026-26030 CRIT 9.9 microsoft semantic_kernel Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `python-1.39.4`. Users sho 3.7%
CVE-2014-0499 HIGH 7.8 adobe adobe_air Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 3.7%
CVE-1999-0289 MED 5.0 apache http_server The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL. 3.7%
CVE-2019-0555 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows Server 3.7%
CVE-2023-36778 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 3.7%
CVE-2003-1580 MED 4.3 apache http_server The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS r 3.7%
CVE-2022-29110 HIGH 7.8 microsoft excel Microsoft Excel Remote Code Execution Vulnerability 3.7%
CVE-2013-2684 MED 6.1 cisco linksys_e4200_firmware Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. 3.7%
CVE-2021-40525 CRIT 9.1 apache james Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. D 3.7%
CVE-2019-8206 CRIT 9.8 adobe acrobat_dc Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to 3.7%
CVE-2020-1460 HIGH 8.6 microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls. An authenticated attacker who successfully exploited the vulnerability could use a specially crafted page 3.7%
CVE-2023-0266 HIGH 7.9 debian debian_linux A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. W 3.7%
CVE-2020-3566 HIGH 8.6 cisco ios_xr A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue managemen 3.7%
CVE-2018-14614 MED 5.5 linux linux_kernel An issue was discovered in the Linux kernel through 4.17.10. There is an out-of-bounds access in __remove_dirty_segment() in fs/f2fs/segment.c when mounting an f2fs image. 3.7%
CVE-2016-4430 HIGH 8.8 apache struts Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors. 3.7%
CVE-2007-5350 HIGH 7.2 microsoft windows_vista Unspecified vulnerability in the Windows Advanced Local Procedure Call (ALPC) in the kernel in Microsoft Windows Vista allows local users to gain privileges via unspecified vectors involving "legacy reply paths." 3.7%
CVE-2019-1756 HIGH 7.2 cisco ios A vulnerability in Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs because the affected software improperly sanitizes use 3.7%
CVE-2018-4246 HIGH 8.8 apple icloud An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affec 3.7%
CVE-2020-16929 HIGH 7.8 microsoft 365_apps <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If t 3.7%
CVE-2017-12624 MED 5.5 apache cxf Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS 3.7%
CVE-2021-20354 HIGH 7.5 ibm websphere_application_server IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883 3.7%
CVE-2018-17620 HIGH 8.8 foxitsoftware phantompdf This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The 3.7%
CVE-2018-17619 HIGH 8.8 foxitsoftware reader This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The 3.7%
CVE-2018-17617 HIGH 8.8 foxitsoftware reader This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The 3.7%
CVE-2018-17616 HIGH 8.8 foxitsoftware phantompdf This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The 3.7%