57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22006 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2019-1895 | CRIT 9.8 | cisco enterprise_nfv_infrastructure_software A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected dev | 2.3% | — |
| CVE-2017-2349 | CRIT 9.9 | juniper junos A command injection vulnerability in the IDP feature of Juniper Networks Junos OS on SRX series devices potentially allows a user with login access to the device to execute shell commands and elevate privileges. Affected releases are Juniper Networks Junos OS | 2.3% | — |
| CVE-2023-39553 | HIGH 7.5 | apache apache-airflow-providers-apache-drill Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with Drill | 2.3% | — |
| CVE-2021-31945 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2019-1130 | HIGH 7.8 | ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129. | 2.3% | |
| CVE-2013-5498 | MED 5.0 | cisco ios_xr The PPTP-ALG component in CRS Carrier Grade Services Engine (CGSE) and ASR 9000 Integrated Service Module (ISM) in Cisco IOS XR allows remote attackers to cause a denial of service (module reset) via crafted packet streams, aka Bug ID CSCue91963. | 2.3% | — |
| CVE-2021-31164 | HIGH 7.5 | apache unomi Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements. | 2.3% | — |
| CVE-2018-8323 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.3% | — |
| CVE-2018-8299 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.3% | — |
| CVE-2016-9418 | HIGH 7.5 | mybb merge_system MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows might allow remote attackers to obtain sensitive information from ACP backups via vectors involving a short name. | 2.3% | — |
| CVE-2022-24289 | HIGH 8.8 | apache cayenne Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Object Persistence (ROP) feature is a web services-based technology that provides object persistence and query functionality to 'remote' appli | 2.3% | — |
| CVE-2021-36937 | HIGH 7.8 | microsoft windows_10 Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-1722 | HIGH 8.1 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2024-26208 | HIGH 7.2 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2023-25754 | CRIT 9.8 | apache airflow Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0. | 2.3% | — |
| CVE-2021-28448 | HIGH 7.8 | microsoft visual_studio_code_kubernetes_tools Visual Studio Code Kubernetes Tools Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2020-3147 | HIGH 7.5 | cisco sf300-08_firmware A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of requests sent to the web inter | 2.3% | — |
| CVE-2011-3290 | HIGH 10.0 | cisco identity_services_engine Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform unspecified other administrative actions via unknown vectors, aka Bug ID CSCts59135. | 2.3% | — |
| CVE-2026-32178 | HIGH 7.5 | microsoft .net Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network. | 2.3% | — |
| CVE-2018-4278 | MED 4.3 | apple icloud In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking. | 2.3% | — |
| CVE-2018-0754 | MED 5.5 | microsoft windows_10 The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 al | 2.3% | — |
| CVE-2015-4306 | HIGH 8.5 | cisco prime_collaboration_assurance The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session read restrictions, and impersonate administrators of arbitrary tenant domains, by discovering a session identifier | 2.3% | — |
| CVE-2024-43515 | HIGH 7.5 | microsoft windows_10_1507 Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability | 2.3% | — |
| CVE-2024-20401 | CRIT 9.8 | cisco secure_email_gateway A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files on the underlying operating system. This vulnerability is due to improper handl | 2.3% | — |