57.044 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
57.044 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1318 | MED 5.9 | microsoft windows_10 A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'. | 3.5% | — |
| CVE-2016-6800 | MED 6.1 | apache ofbiz The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog articles the user input of the summary field as | 3.5% | — |
| CVE-2010-4342 | HIGH 7.1 | linux linux_kernel The aun_incoming function in net/econet/af_econet.c in the Linux kernel before 2.6.37-rc6, when Econet is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending an Acorn Universal Networking (AUN) packet ov | 3.5% | — |
| CVE-2006-4910 | MED 5.0 | cisco ids_sensor_software The web administration interface (mainApp) to Cisco IDS before 4.1(5c), and IPS 5.0 before 5.0(6p1) and 5.1 before 5.1(2) allows remote attackers to cause a denial of service (unresponsive device) via a crafted SSLv2 Client Hello packet. | 3.5% | — |
| CVE-2021-33764 | MED 5.9 | microsoft windows_server_2008 Windows Key Distribution Center Information Disclosure Vulnerability | 3.5% | — |
| CVE-2017-2956 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the JavaScript engine, related to manipulation of the navigation pane. Successful exploitation could lead | 3.5% | — |
| CVE-2017-2955 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the JavaScript engine. Successful exploitation could lead to arbitrary code execution. | 3.5% | — |
| CVE-2010-0741 | HIGH 7.8 | linux linux_kernel The virtio_net_bad_features function in hw/virtio-net.c in the virtio-net driver in the Linux kernel before 2.6.26, when used on a guest OS in conjunction with qemu-kvm 0.11.0 or KVM 83, allows remote attackers to cause a denial of service (guest OS crash, and | 3.5% | — |
| CVE-2014-6154 | HIGH 7.8 | ibm optim_performance_manager Directory traversal vulnerability in IBM Optim Performance Manager for DB2 4.1.0.1 through 4.1.1 on Linux, UNIX, and Windows and IBM InfoSphere Optim Performance Manager for DB2 5.1 through 5.3.1 on Linux, UNIX, and Windows allows remote attackers to access ar | 3.5% | — |
| CVE-2009-3275 | MED 5.0 | microsoft enterprise_library Blocks/Common/Src/Configuration/Manageability/Adm/AdmContentBuilder.cs in Microsoft patterns & practices Enterprise Library (aka EntLib) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many \ (b | 3.5% | — |
| CVE-2025-48989 | HIGH 7.5 | apache tomcat Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, | 3.5% | — |
| CVE-2023-20860 | HIGH 7.5 | vmware spring_framework Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security | 3.5% | — |
| CVE-2014-7809 | MED 6.8 | apache struts Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mechanism. | 3.5% | — |
| CVE-2020-17118 | HIGH 8.1 | microsoft sharepoint_foundation Microsoft SharePoint Remote Code Execution Vulnerability | 3.5% | — |
| CVE-2019-5515 | HIGH 8.8 | vmware fusion VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) and Fusion (11.x before 11.0.3, 10.x before 10.1.6) updates address an out-of-bounds write vulnerability in the e1000 and e1000e virtual network adapters. Exploitation of this issue may lead to code e | 3.5% | — |
| CVE-2011-2104 | MED 4.3 | adobe acrobat Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to cause a denial of service (memory corruption) via unspecified vectors. | 3.5% | — |
| CVE-2008-3800 | HIGH 7.1 | cisco ios Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Communications Manager 4.1 through 6.1, when VoIP is configured, allows remote attackers to cause a denial of service (device or proces | 3.5% | — |
| CVE-2020-27018 | MED 5.5 | trendmicro interscan_messaging_security_virtual_appliance Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow an authenticated attacker to abuse the product's web server and grant access to web resources or parts of loca | 3.5% | — |
| CVE-2013-1182 | HIGH 9.3 | cisco unified_computing_system_6120xp_fabric_interconnect The login page in the Web Console in the Manager component in Cisco Unified Computing System (UCS) before 1.0(2h), 1.1 before 1.1(1j), and 1.3(x) allows remote attackers to bypass LDAP authentication via a malformed request, aka Bug ID CSCtc91207. | 3.5% | — |
| CVE-1999-1084 | MED 4.6 | microsoft windows_nt The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash. | 3.5% | — |
| CVE-2022-41099 | MED 4.6 | microsoft windows_10 BitLocker Security Feature Bypass Vulnerability | 3.5% | — |
| CVE-2019-1850 | HIGH 7.2 | cisco integrated_management_controller_supervisor A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. An attacker | 3.5% | — |
| CVE-2019-16005 | HIGH 7.2 | cisco collaboration_meeting_rooms A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper validation of user-supplied input by the we | 3.5% | — |
| CVE-2019-12690 | HIGH 7.2 | cisco secure_firewall_management_center A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with the privileges of the root user of the underlying operating system. The vulnerability | 3.5% | — |
| CVE-2014-5333 | MED 4.3 | adobe adobe_air Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compile | 3.5% | — |