57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-23193 | MED 5.5 | adobe illustrator Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex | 2.0% | — |
| CVE-2020-9610 | MED 5.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a null pointer vulnerability. Successful exploitation could lead to application denial-of-service. | 2.0% | — |
| CVE-2019-5098 | HIGH 8.6 | amd radeon_550_firmware An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted pixel shader can cause out-of-bounds memory read. An attacker can provide a specially crafted shader file to trigger this vulnerab | 2.0% | — |
| CVE-2015-5736 | HIGH 7.2 | fortinet forticlient The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the callback function in a (1) 0x220024 or (2) 0x220028 ioctl call. | 2.0% | — |
| CVE-2006-0764 | MED 5.1 | cisco anomaly_guard_module The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a "tacacs-server ho | 2.0% | — |
| CVE-2020-29018 | HIGH 8.8 | fortinet fortiweb A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the content of memory and retrieve sensitive data via the redir parameter. | 2.0% | — |
| CVE-2019-1721 | MED 6.5 | cisco telepresence_video_communication_server A vulnerability in the phone book feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to cause the CPU to increase to 100% utilization, causing a denial of service (DoS) condi | 2.0% | — |
| CVE-2019-1697 | MED 6.8 | cisco adaptive_security_appliance_software A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affect | 2.0% | — |
| CVE-2019-1693 | MED 6.5 | cisco adaptive_security_appliance_software A vulnerability in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vu | 2.0% | — |
| CVE-2015-1768 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnera | 2.0% | — |
| CVE-2021-41340 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-41331 | HIGH 7.8 | microsoft windows_10 Windows Media Audio Decoder Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-41330 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2015-4225 | MED 4.0 | cisco nx-os Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devices does not properly implement RBAC health scoring, which allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID | 2.0% | — |
| CVE-1999-1446 | LOW 2.1 | microsoft internet_explorer Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user br | 2.0% | — |
| CVE-2024-26166 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2024-21450 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2024-21440 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2024-21435 | HIGH 8.8 | microsoft windows_11_22h2 Windows OLE Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2023-28250 | CRIT 9.8 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2023-24931 | HIGH 7.5 | microsoft windows_10_1507 Windows Secure Channel Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-21557 | HIGH 7.5 | microsoft windows_10_1607 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | 2.0% | — |
| CVE-2021-25232 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the SQL database. | 2.0% | — |
| CVE-2015-0760 | MED 4.0 | cisco adaptive_security_appliance_software The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows remote authenticated users to bypass XAUTH authentication via crafted IKEv1 packets, aka Bug ID CSCus47259. | 2.0% | — |
| CVE-2024-26214 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC SQL Server ODBC Driver Remote Code Execution Vulnerability | 2.0% | — |