57.020 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
57.020 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1051 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 3.7% | — |
| CVE-2011-5327 | CRIT 9.8 | linux linux_kernel In the Linux kernel before 3.1, an off by one in the drivers/target/loopback/tcm_loop.c tcm_loop_make_naa_tpg() function could result in at least memory corruption. | 3.7% | — |
| CVE-2013-6398 | LOW 2.8 | apache cloudstack The virtual router in Apache CloudStack before 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote attackers to bypass intended restrictions via a request. | 3.7% | — |
| CVE-2021-28456 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 3.7% | — |
| CVE-2017-0231 | MED 4.3 | microsoft edge A spoofing vulnerability exists when Microsoft browsers render SmartScreen Filter, aka "Microsoft Browser Spoofing Vulnerability." | 3.7% | — |
| CVE-2010-2211 | HIGH 9.3 | adobe acrobat Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010- | 3.7% | — |
| CVE-2010-2209 | HIGH 9.3 | adobe acrobat Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010- | 3.7% | — |
| CVE-2010-2207 | HIGH 9.3 | adobe acrobat Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010- | 3.7% | — |
| CVE-2010-2202 | HIGH 9.3 | adobe acrobat Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010- | 3.7% | — |
| CVE-2010-1295 | HIGH 9.3 | adobe acrobat Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2202, CVE-2010- | 3.7% | — |
| CVE-2021-41351 | MED 4.3 | microsoft edge Microsoft Edge (Chrome based) Spoofing on IE Mode | 3.7% | — |
| CVE-2021-34469 | HIGH 8.2 | microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability | 3.7% | — |
| CVE-2025-23359 | HIGH 8.3 | nvidia nvidia_container_toolkit NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lea | 3.7% | — |
| CVE-2016-6798 | CRIT 9.8 | apache sling In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially allowin | 3.7% | — |
| CVE-2019-8174 | HIGH 8.8 | adobe acrobat_dc Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation coul | 3.7% | — |
| CVE-2018-20657 | HIGH 7.5 | f5 traffix_signaling_delivery_controller The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698. | 3.7% | — |
| CVE-2020-1567 | MED 4.2 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacke | 3.7% | — |
| CVE-2014-9164 | HIGH 10.0 | adobe flash_player Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different v | 3.7% | — |
| CVE-2018-0880 | HIGH 7.0 | microsoft windows_10 The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how the virtual registry is managed, aka "Windows Desktop Bridge Elevation of Privilege Vulnerabil | 3.7% | — |
| CVE-2021-43228 | HIGH 7.5 | microsoft windows_10 SymCrypt Denial of Service Vulnerability | 3.7% | — |
| CVE-2021-43219 | HIGH 7.4 | microsoft windows_10 DirectX Graphics Kernel File Denial of Service Vulnerability | 3.7% | — |
| CVE-2021-28465 | HIGH 7.8 | microsoft web_media_extensions Web Media Extensions Remote Code Execution Vulnerability | 3.7% | — |
| CVE-2020-9661 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 17.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution . | 3.7% | — |
| CVE-2020-1169 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context.</p> <p>An attacker could exploit this vu | 3.7% | — |
| CVE-2016-0173 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application | 3.7% | — |