57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-9714 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a security bypass vulnerability. Successful exploitation could lead to privilege escalation . | 2.8% | — |
| CVE-2020-16910 | MED 6.2 | microsoft windows_10 <p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.</p> <p>To exploit this vulne | 2.8% | — |
| CVE-2019-12414 | MED 5.3 | apache superset In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab | 2.8% | — |
| CVE-2016-9212 | HIGH 7.5 | cisco web_security_appliance A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to connect to a secure website over Secure Sockets Layer (SSL) or Trans | 2.8% | — |
| CVE-2007-2389 | HIGH 7.1 | apple quicktime Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not clear potentially sensitive memory before use, which allows remote attackers to read memory from a web browser via unknown vectors related to Java applets. | 2.8% | — |
| CVE-2023-35349 | CRIT 9.8 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2021-31453 | HIGH 7.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 2.8% | — |
| CVE-2021-31451 | HIGH 7.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 2.8% | — |
| CVE-2021-31450 | HIGH 7.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 2.8% | — |
| CVE-2021-31441 | HIGH 7.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 2.8% | — |
| CVE-2020-9561 | HIGH 7.8 | adobe bridge Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | 2.8% | — |
| CVE-2020-9556 | HIGH 7.8 | adobe bridge Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | 2.8% | — |
| CVE-2019-6756 | MED 5.5 | foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF 9.4.0.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malici | 2.8% | — |
| CVE-2014-2176 | HIGH 7.1 | cisco asr_9001 Cisco IOS XR 4.1.2 through 5.1.1 on ASR 9000 devices, when a Trident-based line card is used, allows remote attackers to cause a denial of service (NP chip and line card reload) via malformed IPv6 packets, aka Bug ID CSCun71928. | 2.8% | — |
| CVE-2022-21851 | HIGH 8.8 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-21850 | HIGH 8.8 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2006-1624 | HIGH 7.8 | linux linux_kernel The default configuration of syslogd in the Linux sysklogd package does not enable the -x (disable name lookups) option, which allows remote attackers to cause a denial of service (traffic amplification) via messages with spoofed source IP addresses. | 2.8% | — |
| CVE-2017-3863 | HIGH 8.6 | cisco ios Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a | 2.8% | — |
| CVE-2017-3862 | HIGH 8.6 | cisco ios Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a | 2.8% | — |
| CVE-2017-3861 | HIGH 8.6 | cisco ios Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a | 2.8% | — |
| CVE-2017-3860 | HIGH 8.6 | cisco ios Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a | 2.8% | — |
| CVE-2018-11039 | MED 5.9 | debian debian_linux Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an | 2.8% | — |
| CVE-2008-3812 | HIGH 7.1 | cisco ios Cisco IOS 12.4, when IOS firewall Application Inspection Control (AIC) with HTTP Deep Packet Inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed HTTP transit packet. | 2.8% | — |
| CVE-2022-37021 | CRIT 9.8 | apache geode Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JMX or RMI should upgra | 2.8% | — |
| CVE-2017-14189 | CRIT 9.8 | fortinet fortiweb_manager An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password. | 2.8% | — |