57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-1388 | MED 4.3 | apple safari WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6, and before 4.1 on Mac OS X 10.4, does not properly handle clipboard (1) drag and (2) paste operations for URLs, which allows user-assisted remote attackers to read arbitrary files via a crafted H | 2.7% | — |
| CVE-2023-21538 | HIGH 7.5 | fedoraproject fedora .NET Denial of Service Vulnerability | 2.7% | — |
| CVE-2022-23913 | HIGH 7.5 | apache artemis In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory. | 2.7% | — |
| CVE-2019-0010 | HIGH 7.5 | juniper junos An SRX Series Service Gateway configured for Unified Threat Management (UTM) may experience a system crash with the error message "mbuf exceed" -- an indication of memory buffer exhaustion -- due to the receipt of crafted HTTP traffic. Each crafted HTTP packet | 2.7% | — |
| CVE-2016-1374 | HIGH 8.8 | cisco unified_computing_system_performance_manager The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrary commands via crafted parameters in a GET request, aka Bug ID CSCuy07827. | 2.7% | — |
| CVE-2007-6404 | MED 5.0 | shttp shttp Directory traversal vulnerability in Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URI. | 2.7% | — |
| CVE-2022-29105 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-21915 | MED 6.5 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 2.7% | — |
| CVE-2013-1010 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1008 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1007 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1006 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1005 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1004 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1003 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1002 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1001 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1000 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-0999 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2020-16933 | HIGH 7.0 | microsoft 365_apps <p>A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of | 2.7% | — |
| CVE-2008-2059 | HIGH 7.8 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 allows remote attackers to bypass control-plane ACLs for the device via unknown vectors. | 2.7% | — |
| CVE-2022-29131 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-29129 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-29128 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2020-1507 | HIGH 7.9 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system.</p> <p>To exploit the vulnerabi | 2.7% | — |