IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2019-18190 CRIT 9.8 trendmicro antivirus\+_security_2020 Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances. 2.7%
CVE-2018-17193 MED 6.1 apache nifi The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache Ni 2.7%
CVE-2021-31446 LOW 3.3 foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious f 2.7%
CVE-2020-8269 HIGH 8.8 citrix virtual_apps_and_desktops An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9 2.7%
CVE-2018-17192 MED 6.5 apache nifi The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently appl 2.7%
CVE-2002-0046 MED 5.0 linux linux_kernel Linux kernel, and possibly other operating systems, allows remote attackers to read portions of memory via a series of fragmented ICMP packets that generate an ICMP TTL Exceeded response, which includes portions of the memory in the response packet. 2.7%
CVE-2021-26861 HIGH 7.8 microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability 2.7%
CVE-2016-4968 MED 6.5 fortinet fortiwan The linkreport/tmp/admin_global page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to discover administrator cookies via a GET request. 2.7%
CVE-2006-3287 HIGH 7.5 cisco wireless_control_system Cisco Wireless Control System (WCS) for Linux and Windows 4.0(1) and earlier uses a default administrator username "root" and password "public," which allows remote attackers to gain access (aka bug CSCse21391). 2.7%
CVE-2006-3286 HIGH 7.5 cisco wireless_control_system The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(63) stores a hard-coded username and password in plaintext within unspecified files, which allows remote authenticated users to access the database (aka bug CSCsd1595 2.7%
CVE-2006-3285 HIGH 7.5 cisco wireless_control_system The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) uses an undocumented, hard-coded username and password, which allows remote authenticated users to read, and possibly modify, sensitive configuration data (aka bu 2.7%
CVE-2025-13316 HIGH 8.1 lynxtechnology twonky_server Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and 2.7%
CVE-2021-40485 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 2.7%
CVE-2011-3516 HIGH 7.6 sun jdk Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integr 2.7%
CVE-2023-38226 HIGH 7.8 adobe acrobat Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issu 2.7%
CVE-2023-38223 HIGH 7.8 adobe acrobat Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Access of Uninitialized Pointer that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires use 2.7%
CVE-2014-5711 MED 5.4 microsoft microsoft_tech_companion The Microsoft Tech Companion (aka com.technet) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. 2.7%
CVE-2023-38185 HIGH 8.8 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 2.7%
CVE-2021-27047 HIGH 7.8 microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability 2.7%
CVE-2020-17089 HIGH 7.1 microsoft sharepoint_foundation Microsoft SharePoint Elevation of Privilege Vulnerability 2.7%
CVE-2020-16934 HIGH 7.0 microsoft 365_apps <p>An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges.</p> <p>To exploit this vulnerability, an atta 2.7%
CVE-2020-1582 HIGH 7.8 microsoft 365_apps A remote code execution vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the 2.7%
CVE-2020-1534 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafte 2.7%
CVE-2020-1531 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Accounts Control improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted appli 2.7%
CVE-2020-1478 HIGH 7.8 microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri 2.7%