57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-5029 | HIGH 8.8 | debian debian_linux The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a r | 2.2% | — |
| CVE-2011-2584 | HIGH 7.5 | cisco show_and_share Cisco Show and Share 5(2), 5.2(1), and 5.2(2) before 5.2(2.1) allows remote attackers to access the (1) Encoders and Pull Configurations, (2) Push Configurations, (3) Video Encoding Formats, and (4) Transcoding administration pages, and cause a denial of servi | 2.2% | — |
| CVE-2010-0686 | HIGH 7.5 | vmware esx_server WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability. | 2.2% | — |
| CVE-2025-29814 | CRIT 9.3 | microsoft partner_center Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. | 2.2% | — |
| CVE-2024-21348 | HIGH 7.5 | microsoft windows_10_1507 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 2.2% | — |
| CVE-2019-5618 | HIGH 7.8 | a-pdf wav_to_mp3 A-PDF WAV to MP3 version 1.0.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow. | 2.2% | — |
| CVE-2002-0720 | HIGH 7.2 | microsoft windows_2000 A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code. | 2.2% | — |
| CVE-2020-3451 | MED 4.7 | cisco rv340_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series Routers could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands on the underlying operating system (OS) as a | 2.2% | — |
| CVE-2019-8097 | MED 5.3 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an internal ip disclosure vulnerability. Successfu | 2.2% | — |
| CVE-2015-7749 | HIGH 7.8 | juniper junos The PFE daemon in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of service via an unspecified connection request to the "host-OS." | 2.2% | — |
| CVE-2015-6327 | HIGH 7.8 | cisco adaptive_security_appliance_software The IKEv1 implementation in Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.8), 9.2 before 9.2(4), and 9.3 before 9.3(3) allow | 2.2% | — |
| CVE-2006-7216 | MED 4.0 | apache derby Apache Derby before 10.2.1.6 does not determine privilege requirements for lock table statements at compilation time, and consequently does not enforce privilege requirements at execution time, which allows remote authenticated users to lock arbitrary tables. | 2.2% | — |
| CVE-2022-38036 | HIGH 7.5 | microsoft windows_11 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | 2.2% | — |
| CVE-2022-33645 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability | 2.2% | — |
| CVE-2018-0181 | HIGH 7.3 | cisco cisco_policy_suite_diameter_routing_agent A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software could allow an unauthenticated, remote attacker to modify key-value pairs for short-lived events stored by the Redis se | 2.2% | — |
| CVE-2017-3151 | MED 6.1 | apache atlas Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality. | 2.2% | — |
| CVE-2016-6397 | CRIT 9.8 | cisco ip_interoperability_and_collaboration_system A vulnerability in the interdevice communications interface of the Cisco IP Interoperability and Collaboration System (IPICS) Universal Media Services (UMS) could allow an unauthenticated, remote attacker to modify configuration parameters of the UMS and cause | 2.2% | — |
| CVE-2014-3413 | CRIT 9.8 | juniper junos_space The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers to obtain sensitive information and consequently obtain administrative control by leveraging database access. | 2.2% | — |
| CVE-2025-24993 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | 2.2% | |
| CVE-2024-38160 | CRIT 9.1 | microsoft windows_10_1607 Windows Network Virtualization Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2024-38159 | CRIT 9.1 | microsoft windows_10_1607 Windows Network Virtualization Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-21683 | MED 6.5 | jenkins jenkins The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Overall/Read permission (Windows controller) or Job/Workspace p | 2.2% | — |
| CVE-2013-6012 | HIGH 8.5 | juniper junos Juniper Junos 12.1X44 before 12.1.X44-D20 and 12.1X45 before 12.1X45-D15, when the no-validate option is enabled, does not properly handle configuration validation errors during the config commit phase of the boot-up sequence, which allows remote attackers to | 2.2% | — |
| CVE-2013-1148 | HIGH 7.8 | cisco ios The General Responder implementation in the IP Service Level Agreement (SLA) feature in Cisco IOS 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S allows remote attackers to cause a denial of service (device reload) v | 2.2% | — |
| CVE-2021-42315 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2.2% | — |