57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1043 | MED 6.4 | microsoft windows_10 A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successf | 2.7% | — |
| CVE-2016-7544 | HIGH 7.5 | cryptopp crypto\+\+ Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed. | 2.7% | — |
| CVE-2009-3760 | HIGH 7.5 | citrix xencenterweb Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these | 2.7% | — |
| CVE-1999-1235 | MED 4.6 | microsoft internet_explorer Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to | 2.7% | — |
| CVE-2020-1944 | CRIT 9.8 | apache traffic_server There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions. | 2.7% | — |
| CVE-2011-0817 | HIGH 10.0 | sun jdk Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, a | 2.7% | — |
| CVE-2008-1392 | HIGH 10.0 | vmware ace The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the console of the guest OS accessible through anonymous VIX API calls, which has unknown impact and attack vectors. | 2.7% | — |
| CVE-2018-3933 | HIGH 8.8 | antennahouse office_server_document_converter An exploitable out-of-bounds write exists in the Microsoft Word document conversion functionality of the Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312). A crafted Microsoft Word (DOC) document can lead to an out | 2.7% | — |
| CVE-2016-8746 | MED 5.9 | apache ranger Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true. | 2.7% | — |
| CVE-2026-62893 | CRIT 9.8 | microsoft windows_10_1607 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | 2.7% | — |
| CVE-2021-33740 | HIGH 7.8 | microsoft windows_10 Windows Media Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2017-1000371 | HIGH 7.8 | linux linux_kernel The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then the stack will be grown down to 0x80000000, and as the PIE bin | 2.7% | — |
| CVE-2022-31659 | HIGH 7.2 | vmware access_connector VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution. | 2.7% | — |
| CVE-2021-32785 | MED 5.3 | debian debian_linux mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. When mod_auth_openidc versions prior to 2.4.9 are configured t | 2.7% | — |
| CVE-2010-0146 | MED 6.8 | cisco security_agent Directory traversal vulnerability in the Management Center for Cisco Security Agents 6.0 allows remote authenticated users to read arbitrary files via unspecified vectors. | 2.7% | — |
| CVE-2009-3294 | MED 5.0 | php php The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" string in the | 2.7% | — |
| CVE-2020-16969 | HIGH 7.1 | microsoft exchange_server <p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user.</p> <p>To exploit the | 2.7% | — |
| CVE-2022-30152 | HIGH 7.5 | microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.7% | — |
| CVE-2013-7445 | HIGH 7.8 | linux linux_kernel The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that pr | 2.7% | — |
| CVE-2006-0340 | HIGH 7.1 | cisco ios Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network | 2.7% | — |
| CVE-2023-47804 | HIGH 8.8 | apache openoffice Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject | 2.7% | — |
| CVE-2021-38645 | HIGH 7.8 | microsoft azure_automation_state_configuration Open Management Infrastructure Elevation of Privilege Vulnerability | 2.7% | |
| CVE-2024-23666 | HIGH 7.5 | fortinet fortianalyzer A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and | 2.7% | — |
| CVE-2021-20557 | HIGH 7.2 | ibm security_guardium IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 199184. | 2.7% | — |
| CVE-2019-12812 | CRIT 9.8 | activesoft mybuilder MyBuilder viewer before 6.2.2019.814 allow an attacker to execute arbitrary command via specifically crafted configuration file. This can be leveraged for code execution. | 2.7% | — |