56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.571 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-3331 | CRIT 9.8 | cisco rv110w_wireless-n_vpn_firewall_firmware A vulnerability in the web-based management interface of Cisco RV110W Wireless-N VPN Firewall and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to im | 41.7% | — |
| CVE-2022-21999 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 41.7% | |
| CVE-2024-38476 | CRIT 9.8 | apache http_server Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2 | 41.6% | — |
| CVE-2017-5030 | HIGH 8.8 | debian debian_linux Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page. | 41.6% | |
| CVE-2018-1026 | HIGH 8.8 | microsoft office A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-20 | 41.6% | — |
| CVE-2022-36533 | MED 5.4 | syncovery syncovery Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability. | 41.6% | — |
| CVE-2007-1749 | HIGH 9.3 | microsoft internet_explorer Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which t | 41.5% | — |
| CVE-2016-0063 | HIGH 8.8 | microsoft internet_explorer Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016 | 41.5% | — |
| CVE-2020-9590 | HIGH 7.8 | adobe digital_negative_software_development_kit Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution. | 41.5% | — |
| CVE-2007-6258 | HIGH 7.5 | apache mod_jk Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header. | 41.5% | — |
| CVE-2013-3185 | MED 5.0 | microsoft active_directory_federation_services Microsoft Active Directory Federation Services (AD FS) 1.x through 2.1 on Windows Server 2003 R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 allows remote attackers to obtain sensitive information about the service account, and possibly co | 41.4% | — |
| CVE-2007-2217 | HIGH 9.3 | kodak image_viewer Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF) file. | 41.4% | — |
| CVE-2019-0841 | HIGH 7.8 | ransomware microsoft windows_10_1703 An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-08 | 41.4% | |
| CVE-2002-2007 | MED 5.0 | apache tomcat The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp | 41.4% | — |
| CVE-2009-0553 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers prese | 41.4% | — |
| CVE-2009-1930 | HIGH 10.0 | microsoft windows_2000 The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client u | 41.4% | — |
| CVE-2007-2216 | HIGH 9.3 | microsoft internet_explorer The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation, which allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a crafted DLL | 41.4% | — |
| CVE-2024-38178 | HIGH 7.5 | microsoft windows_10_1507 Scripting Engine Memory Corruption Vulnerability | 41.4% | |
| CVE-2022-44666 | HIGH 7.8 | microsoft windows_10 Windows Contacts Remote Code Execution Vulnerability | 41.4% | — |
| CVE-2002-0866 | HIGH 7.5 | microsoft virtual_machine Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc with th | 41.4% | — |
| CVE-2011-0966 | MED 6.8 | cisco ciscoworks_common_services Directory traversal vulnerability in cwhp/auditLog.do in the Homepage Auditing component in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, aka Bug ID CSCto35577. | 41.3% | — |
| CVE-2016-3386 | HIGH 7.5 | microsoft edge The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE | 41.3% | — |
| CVE-2022-30129 | HIGH 8.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 41.3% | — |
| CVE-2005-0057 | HIGH 7.5 | microsoft windows_2000 The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow. | 41.3% | — |
| CVE-2006-6134 | HIGH 7.5 | microsoft windows_media_player Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and ex | 41.3% | — |