IT
57.044 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

57.044 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2021-27058 HIGH 7.8 microsoft 365_apps Microsoft Office ClickToRun Remote Code Execution Vulnerability 3.5%
CVE-2021-26433 HIGH 7.5 microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability 3.5%
CVE-2019-5589 HIGH 7.8 fortinet forticlient An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control over the directory in which FortiClientOnlineInstaller.exe resides to execute arbitrary code on the sy 3.5%
CVE-2015-2114 MED 6.8 hp support_solution_framework HP Support Solution Framework before 11.51.0049 allows remote attackers to download an arbitrary program onto a client machine and execute this program via unspecified vectors. 3.5%
CVE-2012-0803 CRIT 9.8 apache cxf The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as part of a SOAP request. 3.5%
CVE-2008-0600 HIGH 7.2 linux linux_kernel The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different vulnerability 3.5%
CVE-2021-28553 HIGH 8.8 adobe acrobat Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary 3.5%
CVE-2019-19447 HIGH 7.8 linux linux_kernel In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c. 3.5%
CVE-2023-21552 HIGH 7.8 microsoft windows_10_1607 Windows GDI Elevation of Privilege Vulnerability 3.5%
CVE-2020-24588 LOW 3.5 arista c-100_firmware The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU fr 3.5%
CVE-2019-0654 MED 4.3 microsoft edge A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'. 3.5%
CVE-2009-3902 MED 5.0 cherokee cherokee_httpd Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (slash backslash dot dot) in the URL. 3.5%
CVE-2000-1027 MED 5.0 cisco pix_firewall_software Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive mode is established. 3.5%
CVE-2022-28242 HIGH 7.8 adobe acrobat Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of thi 3.5%
CVE-2010-3081 HIGH 7.8 linux linux_kernel The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to gain privi 3.5%
CVE-2020-3211 HIGH 7.2 cisco ios_xe A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device. The vulnerability is due to improper input sanitiz 3.5%
CVE-2026-50509 HIGH 7.8 microsoft windows_10_1607 Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally. 3.5%
CVE-2013-3384 HIGH 9.0 cisco ironport_asyncos The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550; Email Security Appliance devices before 7.1.5-104, 7.3 before 7.3.2-026, 7.5 before 7.5.2-203, and 7.6 before 7.6.3- 3.5%
CVE-2021-42284 MED 6.8 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 3.5%
CVE-2021-28564 HIGH 8.8 adobe acrobat Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Out-of-bounds Write vulnerability within the ImageTool component. An unauthenticated attacker could leverage this 3.5%
CVE-2019-16995 HIGH 7.5 linux linux_kernel In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d. 3.5%
CVE-2008-3804 HIGH 7.1 cisco ios Unspecified vulnerability in the Multi Protocol Label Switching (MPLS) Forwarding Infrastructure (MFI) in Cisco IOS 12.2 and 12.4 allows remote attackers to cause a denial of service (memory corruption) via crafted packets for which the software path is used. 3.5%
CVE-2017-15698 MED 5.9 apache tomcat_native When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefor 3.5%
CVE-2023-24892 HIGH 8.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability 3.5%
CVE-2018-8168 MED 5.4 microsoft sharepoint_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft 3.5%