57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-41704 | HIGH 7.5 | apache batik A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16. | 2.4% | — |
| CVE-2004-0077 | HIGH 7.2 | linux linux_kernel The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to | 2.4% | — |
| CVE-2021-31943 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2020-36277 | HIGH 7.5 | debian debian_linux Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c. | 2.4% | — |
| CVE-2020-25645 | HIGH 7.5 | canonical ubuntu_linux A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints t | 2.4% | — |
| CVE-2019-1170 | HIGH 7.9 | microsoft windows_10 An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox escape. An attacker who successfully exploited the vulnerability could use the sandbox escape to elevate privileges on an affected system. To | 2.4% | — |
| CVE-2004-1759 | MED 5.0 | cisco call_manager Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning. | 2.4% | — |
| CVE-2025-59517 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. | 2.4% | — |
| CVE-2023-36720 | HIGH 7.5 | microsoft windows_10_1607 Windows Mixed Reality Developer Tools Denial of Service Vulnerability | 2.4% | — |
| CVE-2023-36703 | HIGH 7.5 | microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability | 2.4% | — |
| CVE-2021-26606 | CRIT 9.8 | dreamsecurity magicline4nx.exe A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certificate. An attacker could exploit this vulnerability by sending a crafted HTTP re | 2.4% | — |
| CVE-2016-7476 | HIGH 7.5 | f5 big-ip_access_policy_manager The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, APM, ASM, GTM, Link Controller, PEM, PSM, and WebSafe 11.6.0 before 11.6.0 HF6, 11.5.0 before 11.5.3 HF2, and 11.3.0 before 11.4.1 HF10 may suffer from a memory leak while handling certain ty | 2.4% | — |
| CVE-2026-42899 | HIGH 7.5 | microsoft .net Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 2.4% | — |
| CVE-2022-30208 | MED 6.5 | microsoft windows_10 Windows Security Account Manager (SAM) Denial of Service Vulnerability | 2.4% | — |
| CVE-2020-4854 | CRIT 9.8 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-For | 2.4% | — |
| CVE-2017-5044 | MED 6.3 | debian debian_linux Heap buffer overflow in filter processing in Skia in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | 2.4% | — |
| CVE-2026-40047 | CRIT 9.1 | apache camel Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-docling component invokes the external `docling` command-line tool by assembling an argument list in DoclingProducer | 2.4% | — |
| CVE-2022-20710 | CRIT 10.0 | cisco rv340_firmware Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot | 2.4% | — |
| CVE-2023-36789 | HIGH 7.2 | microsoft skype_for_business_server Skype for Business Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2020-9652 | HIGH 7.8 | adobe premiere_pro Adobe Premiere Pro versions 14.2 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution . | 2.4% | — |
| CVE-2023-20101 | CRIT 9.8 | cisco emergency_responder A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the pr | 2.4% | — |
| CVE-2022-22037 | HIGH 7.5 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 2.4% | — |
| CVE-2014-2196 | HIGH 9.3 | cisco wide_area_application_services Cisco Wide Area Application Services (WAAS) 5.1.1 before 5.1.1e, when SharePoint prefetch optimization is enabled, allows remote SharePoint servers to execute arbitrary code via a malformed response, aka Bug ID CSCue18479. | 2.4% | — |
| CVE-2013-3463 | MED 4.3 | cisco adaptive_security_appliance The protocol-inspection feature on Cisco Adaptive Security Appliances (ASA) devices does not properly implement the idle timeout, which allows remote attackers to cause a denial of service (connection-table exhaustion) via crafted requests that use an inspecte | 2.4% | — |
| CVE-2022-28841 | HIGH 7.8 | adobe bridge Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 2.4% | — |