57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-33639 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2020-17052 | HIGH 7.5 | microsoft edge Scripting Engine Memory Corruption Vulnerability | 2.7% | — |
| CVE-2020-13953 | MED 5.3 | apache tapestry In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run. | 2.7% | — |
| CVE-2015-0010 | LOW 1.9 | microsoft windows_7 The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Serv | 2.6% | — |
| CVE-2022-26926 | HIGH 7.8 | microsoft windows_10 Windows Address Book Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2019-6746 | MED 5.5 | foxitsoftware foxit_studio_photo This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Studio Photo 3.6.6. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious | 2.6% | — |
| CVE-2022-30192 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2.6% | — |
| CVE-2020-1647 | CRIT 9.8 | juniper junos On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free vulnerability can lead to a Denial of Service (DoS) or Remote Code Execution (RCE) due to processing of a specific HTTP message. Continued p | 2.6% | — |
| CVE-2019-0569 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 2.6% | — |
| CVE-2019-0554 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 2.6% | — |
| CVE-2019-0549 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 2.6% | — |
| CVE-2019-0536 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 2.6% | — |
| CVE-2008-3803 | MED 5.1 | cisco ios A "logic error" in Cisco IOS 12.0 through 12.4, when a Multiprotocol Label Switching (MPLS) VPN with extended communities is configured, sometimes causes a corrupted route target (RT) to be used, which allows remote attackers to read traffic from other VPNs in | 2.6% | — |
| CVE-2005-3788 | MED 5.4 | cisco adaptive_security_appliance_software Race condition in Cisco Adaptive Security Appliance (ASA) 7.0(0), 7.0(2), and 7.0(4), when running with an Active/Standby configuration and when the failover LAN interface fails, allows remote attackers to cause a denial of service (standby firewall failure) b | 2.6% | — |
| CVE-2023-35643 | HIGH 7.5 | microsoft windows_server_2012 DHCP Server Service Information Disclosure Vulnerability | 2.6% | — |
| CVE-2021-34439 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2020-3401 | MED 6.5 | cisco sd-wan_firmware A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to | 2.6% | — |
| CVE-2019-9855 | CRIT 9.8 | libreoffice libreoffice LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-inst | 2.6% | — |
| CVE-2017-5077 | HIGH 8.8 | google chrome Insufficient validation of untrusted input in Skia in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | 2.6% | — |
| CVE-2021-27067 | MED 6.5 | microsoft azure_devops_server Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability | 2.6% | — |
| CVE-2018-0090 | HIGH 7.5 | cisco nx-os A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote attacker to bypass configured ACLs on the management interface. This could allow traffic to be forwarded to th | 2.6% | — |
| CVE-2014-0649 | HIGH 9.0 | cisco secure_access_control_system The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remote authenticated users to obtain superadmin access via a request to this interface, aka Bug ID CSCud75180. | 2.6% | — |
| CVE-2012-0765 | MED 4.3 | adobe robohelp Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 8 and 9 for Word allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to certain .htm files in (1) template_stock and (2) template_csh directories. | 2.6% | — |
| CVE-2020-3381 | HIGH 8.8 | cisco sd-wan_firmware A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files on a targeted system. The vulnerability is | 2.6% | — |
| CVE-2015-4307 | HIGH 9.0 | cisco prime_collaboration_provisioning The web framework in Cisco Prime Collaboration Provisioning before 11.0 allows remote authenticated users to bypass intended access restrictions and create administrative accounts via a crafted URL, aka Bug ID CSCut64111. | 2.6% | — |