57.044 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
57.044 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-7665 | MED 6.1 | apache nifi In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient. | 3.5% | — |
| CVE-2012-2448 | HIGH 7.5 | vmware esx VMware ESXi 3.5 through 5.0 and ESX 3.5 through 4.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via NFS traffic. | 3.5% | — |
| CVE-2020-9723 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 3.5% | — |
| CVE-2020-9594 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | 3.5% | — |
| CVE-2008-3807 | HIGH 9.3 | cisco ios Cisco IOS 12.2 and 12.3 on Cisco uBR10012 series devices, when linecard redundancy is configured, enables a read/write SNMP service with "private" as the community, which allows remote attackers to obtain administrative access by guessing this community and se | 3.5% | — |
| CVE-2022-47943 | HIGH 8.1 | linux linux_kernel An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is an out-of-bounds read and OOPS for SMB2_WRITE, when there is a large length in the zero DataOffset case. | 3.5% | — |
| CVE-2018-4126 | HIGH 7.8 | apple icloud A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7. | 3.5% | — |
| CVE-2018-0175 | HIGH 8.0 | cisco ios Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute | 3.5% | |
| CVE-2006-5288 | HIGH 10.0 | cisco 2700_wireless_location_appliance Cisco 2700 Series Wireless Location Appliances before 2.1.34.0 have a default administrator username "root" and password "password," which allows remote attackers to obtain administrative privileges, aka Bug ID CSCsb92893. | 3.5% | — |
| CVE-2022-21904 | HIGH 7.5 | microsoft windows_10 Windows GDI Information Disclosure Vulnerability | 3.5% | — |
| CVE-2004-1834 | LOW 2.1 | apache http_server mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information. | 3.5% | — |
| CVE-2014-0228 | LOW 3.5 | apache hive Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI. | 3.5% | — |
| CVE-2024-38021 | HIGH 8.8 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 3.5% | — |
| CVE-2014-2842 | HIGH 7.8 | juniper screenos Juniper ScreenOS 6.3 and earlier allows remote attackers to cause a denial of service (crash and restart or failover) via a malformed SSL/TLS packet. | 3.5% | — |
| CVE-2018-0882 | HIGH 7.0 | microsoft windows_10 The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how the virtual registry is managed, aka "Windows Desktop Bridge Elevation of Privilege Vulnerabil | 3.5% | — |
| CVE-2025-49741 | HIGH 7.4 | microsoft edge_chromium No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 3.5% | — |
| CVE-2008-3526 | HIGH 7.8 | linux linux_kernel Integer overflow in the sctp_setsockopt_auth_key function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel 2.6.24-rc1 through 2.6.26.3 allows remote attackers to cause a denial of service (panic) or pos | 3.5% | — |
| CVE-2025-9478 | HIGH 8.8 | google chrome Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | 3.5% | — |
| CVE-2017-11863 | MED 6.1 | microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to trick a user into loading a page containing malicious content, due to how the Edge Content Security Policy (CSP) val | 3.5% | — |
| CVE-2015-4512 | MED 6.4 | mozilla firefox gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface creation followed by 16-bit color-depth surface display, which allows remote attackers to obtain sensitive inform | 3.5% | — |
| CVE-2024-39420 | HIGH 7.0 | adobe acrobat Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, 24.002.20965, 24.002.20964, 24.001.30123, 24.003.20054 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary co | 3.5% | — |
| CVE-2018-0409 | HIGH 7.5 | cisco telepresence_video_communication_server A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) and the Cisco TelePresence Video Communication Server (VCS) and Expressway could allow an unauthenticated, remote attacker to cause a tempor | 3.5% | — |
| CVE-2017-3790 | HIGH 8.6 | cisco expressway A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software could allow an unauthenticated, remote attacker to cause a reload of the affected system, resulting in a denial of service | 3.5% | — |
| CVE-2015-4184 | MED 5.0 | cisco email_security_appliance The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8.5.6-074 allows remote attackers to bypass intended e-mail restrictions via a malformed DNS SPF record, aka Bug IDs CSCuu35853 and CSCuu37733. | 3.5% | — |
| CVE-2001-1518 | LOW 2.1 | microsoft windows_2000 RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service. NOTE: the vendor | 3.5% | — |