57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-24532 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2020-3158 | CRIT 9.1 | cisco smart_software_manager_on-prem A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to access a sensitive part of the system with a high-privileged account. The vulnerability is due to a system account | 2.6% | — |
| CVE-2016-6799 | HIGH 7.5 | apache cordova Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular buffers on the device. By default, a maximu | 2.6% | — |
| CVE-2019-0759 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Print Spooler does not properly handle objects in memory, aka 'Windows Print Spooler Information Disclosure Vulnerability'. | 2.6% | — |
| CVE-2017-0174 | MED 6.5 | microsoft windows_10 Windows NetBIOS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it improperly handles N | 2.6% | — |
| CVE-2026-27914 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally. | 2.6% | — |
| CVE-2023-26425 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker cou | 2.6% | — |
| CVE-2022-30657 | HIGH 7.8 | adobe incopy Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi | 2.6% | — |
| CVE-2022-30655 | HIGH 7.8 | adobe incopy Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi | 2.6% | — |
| CVE-2022-22942 | HIGH 7.8 | vmware photon_os The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer. | 2.6% | — |
| CVE-2021-42357 | MED 6.1 | apache knox When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially crafted request parameter could be used to redirect the user to a page controlled by a | 2.6% | — |
| CVE-2019-7041 | HIGH 8.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a security bypass vulnerability. Successful exploitation could lead to privilege escalation. | 2.6% | — |
| CVE-2014-2177 | HIGH 9.0 | cisco rv120w The network-diagnostics administration interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote authenticated users to execute arbitrary commands via a crafted | 2.6% | — |
| CVE-2013-6972 | MED 5.0 | cisco webex_training_center Cisco WebEx Training Center allows remote attackers to discover session numbers, and bypass host approval for audio-conference attendance, by reading HTML source code, aka Bug ID CSCul57126. | 2.6% | — |
| CVE-2013-4387 | MED 6.1 | linux linux_kernel net/ipv6/ip6_output.c in the Linux kernel through 3.11.4 does not properly determine the need for UDP Fragmentation Offload (UFO) processing of small packets after the UFO queueing of a large packet, which allows remote attackers to cause a denial of service ( | 2.6% | — |
| CVE-2022-26903 | HIGH 7.8 | microsoft excel Windows Graphics Component Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2019-7999 | MED 6.5 | adobe photoshop_cc Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound read vulnerability. Successful exploitation could lead to memory leak. | 2.6% | — |
| CVE-2019-7133 | MED 6.5 | adobe bridge_cc Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.6% | — |
| CVE-2018-3995 | HIGH 8.8 | foxitsoftware phantompdf An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.2.0.9297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution | 2.6% | — |
| CVE-2018-3944 | HIGH 8.8 | foxitsoftware phantompdf An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution | 2.6% | — |
| CVE-2018-3943 | HIGH 8.8 | foxitsoftware phantompdf An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution | 2.6% | — |
| CVE-2011-0259 | HIGH 7.6 | apple itunes CoreFoundation, as used in Apple iTunes before 10.5, does not properly perform string tokenization, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vector | 2.6% | — |
| CVE-2021-40463 | HIGH 7.7 | microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.6% | — |
| CVE-2014-2522 | MED 4.0 | haxx curl curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS backend, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when ac | 2.6% | — |
| CVE-2007-4263 | HIGH 8.5 | cisco ios Unspecified vulnerability in the server side of the Secure Copy (SCP) implementation in Cisco 12.2-based IOS allows remote authenticated users to read, write or overwrite any file on the device's filesystem via unknown vectors. | 2.6% | — |