57.065 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.065 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2012-2003 | MED 6.8 | hp insight_management_agents Cross-site request forgery (CSRF) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | 1.9% | — |
| CVE-2010-0903 | HIGH 7.8 | oracle database_server Unspecified vulnerability in the Net Foundation Layer component in Oracle Database Server 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1, when running on Windows, allows remote attackers to affect availability via unknown vectors. | 1.9% | — |
| CVE-2008-4281 | HIGH 9.3 | vmware esx Directory traversal vulnerability in VMWare ESXi 3.5 before ESXe350-200810401-O-UG and ESX 3.5 before ESX350-200810201-UG allows administrators with the Datastore.FileManagement privilege to gain privileges via unknown vectors. | 1.9% | — |
| CVE-2023-36890 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Information Disclosure Vulnerability | 1.9% | — |
| CVE-2018-11783 | HIGH 7.5 | apache traffic_server sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 | 1.9% | — |
| CVE-2021-26607 | HIGH 8.1 | tobesoft nexacro An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems. | 1.9% | — |
| CVE-2021-21089 | LOW 3.3 | adobe acrobat_dc Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to locally escala | 1.9% | — |
| CVE-2020-3371 | MED 6.3 | cisco integrated_management_controller A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code and execute arbitrary commands at the underlying operating system level. The vulnerability is due to insufficie | 1.9% | — |
| CVE-2018-0251 | MED 6.1 | cisco adaptive_security_appliance_software A vulnerability in the Web Server Authentication Required screen of the Clientless Secure Sockets Layer (SSL) VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) | 1.9% | — |
| CVE-2010-0531 | MED 4.3 | apple itunes Apple iTunes before 9.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 podcast file. | 1.9% | — |
| CVE-2009-0868 | MED 6.8 | fujitsu jasmine2000 CRLF injection vulnerability in the WebLink template in Fujitsu Jasmine2000 Enterprise Edition allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | 1.9% | — |
| CVE-2021-1518 | MED 6.3 | cisco firepower_device_manager_on-box A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. This vulnerability is due to insufficient | 1.9% | — |
| CVE-2020-17057 | HIGH 7.0 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2019-17021 | MED 5.3 | mozilla firefox During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerabil | 1.9% | — |
| CVE-2018-4130 | HIGH 8.8 | apple icloud An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" | 1.9% | — |
| CVE-2017-9483 | CRIT 9.8 | cisco dpc3939_firmware The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows Network Processor (NP) Linux users to obtain root access to the Application Processor (AP) Linux system via shell metacharacters in commands. | 1.9% | — |
| CVE-2015-6377 | HIGH 7.8 | cisco virtual_topology_system Cisco Virtual Topology System (VTS) 2.0(0) and 2.0(1) allows remote attackers to cause a denial of service (CPU and memory consumption, and TCP port outage) via a flood of crafted TCP packets, aka Bug ID CSCux13379. | 1.9% | — |
| CVE-2023-33127 | HIGH 8.1 | microsoft .net .NET and Visual Studio Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2019-1825 | HIGH 8.1 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the s | 1.9% | — |
| CVE-2019-1824 | HIGH 8.1 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the s | 1.9% | — |
| CVE-2021-36014 | LOW 3.3 | adobe media_encoder Adobe Media Encoder version 15.2 (and earlier) is affected by an uninitialized pointer vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to read arbitrary file system information in the context o | 1.9% | — |
| CVE-2011-2604 | HIGH 7.1 | intel g41_driver The Intel G41 driver 6.14.10.5355 on Windows XP SP3 allows remote attackers to cause a denial of service (system crash) via a crafted web page that is visited with Google Chrome or Mozilla Firefox, as demonstrated by the lots-of-polys-example.html test page in | 1.9% | — |
| CVE-2011-2602 | HIGH 7.1 | nvidia geforce_310_driver The NVIDIA Geforce 310 driver 6.14.12.7061 on Windows XP SP3 allows remote attackers to cause a denial of service (system crash) via a crafted web page that is visited with Google Chrome or Mozilla Firefox, as demonstrated by the lots-of-polys-example.html tes | 1.9% | — |
| CVE-2008-4326 | MED 4.3 | phpmyadmin phpmyadmin The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via a NUL byte inside a "</ | 1.9% | — |
| CVE-2021-38631 | MED 4.4 | microsoft windows_10 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | 1.9% | — |