57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1572 | HIGH 7.5 | paloaltonetworks pan-os PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files. | 2.5% | — |
| CVE-2017-15693 | HIGH 7.5 | apache geode In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objects to be deserialized. A user with DATA:WRITE access to the cluster may be able to cause remote code | 2.5% | — |
| CVE-2024-28752 | CRIT 9.3 | apache cxf A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the d | 2.5% | — |
| CVE-2023-21585 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabi | 2.5% | — |
| CVE-2015-0757 | MED 5.0 | cisco identity_services_engine_software The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote attackers to obtain sensitive information by reading web pages, as demonstrated by MnT reports, aka Bug ID CSC | 2.5% | — |
| CVE-2021-40465 | HIGH 7.8 | microsoft windows_10 Windows Text Shaping Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-36161 | CRIT 9.8 | apache dubbo Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean with special toString method. In the latest version, we fix the toString call in timeout, cache and some other | 2.5% | — |
| CVE-2021-21069 | HIGH 7.8 | adobe creative_cloud_desktop_application Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a local privilege escalation vulnerability that could allow an attacker to call functions against the installer to perform high privileged actions. Exploitation of this issue doe | 2.5% | — |
| CVE-2013-6357 | MED 6.8 | apache tomcat Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as de | 2.5% | — |
| CVE-2013-0682 | HIGH 7.5 | cogentdatahub cascade_datahub Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 do not properly handle exceptions, which allows remote attackers to cause a denial of service (applic | 2.5% | — |
| CVE-2020-5015 | HIGH 7.5 | ibm elastic_storage_server IBM Elastic Storage System 6.0.0 through 6.0.1.2 and IBM Elastic Storage Server 5.3.0 through 5.3.6.2 could allow a remote attacker to cause a denial of service by sending malformed UDP requests. IBM X-Force ID: 193486. | 2.5% | — |
| CVE-2023-35385 | CRIT 9.8 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2023-21614 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabi | 2.5% | — |
| CVE-2023-21613 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabi | 2.5% | — |
| CVE-2022-30161 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2022-30153 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2018-5544 | HIGH 7.5 | f5 big-ip_access_policy_manager When the F5 BIG-IP APM 13.0.0-13.1.1 or 12.1.0-12.1.3 renders certain pages (pages with a logon agent or a confirm box), the BIG-IP APM may disclose configuration information such as partition and agent names via URI parameters. | 2.5% | — |
| CVE-2017-9458 | CRIT 9.8 | paloaltonetworks pan-os XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive inform | 2.5% | — |
| CVE-2024-35252 | HIGH 7.5 | microsoft azure_storage_data_movement_library Azure Storage Movement Client Library Denial of Service Vulnerability | 2.5% | — |
| CVE-2021-24082 | MED 4.3 | microsoft windows_10 Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability | 2.5% | — |
| CVE-2019-1873 | HIGH 8.6 | cisco asa_5506-x_firmware A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reboot unexpectedly. The vulnerability is due to | 2.5% | — |
| CVE-2017-7336 | CRIT 9.8 | fortinet fortiwlm A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges. | 2.5% | — |
| CVE-2023-38157 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 2.5% | — |
| CVE-2020-1173 | MED 6.8 | microsoft power_bi_report_server A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially crafted payload and sending it to the user. | 2.5% | — |
| CVE-2019-0950 | MED 5.7 | microsoft sharepoint_foundation A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019- | 2.5% | — |