56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.571 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2006-3435 | HIGH 9.3 | microsoft office PowerPoint in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac does not properly parse the slide notes field in a document, which allows remote user-assisted attackers to execute arbitrary code via crafted data in this field, which triggers an er | 36.3% | — |
| CVE-2012-0284 | HIGH 9.3 | cisco linksys_playerpt_activex_control Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireless-G PTZ Internet video camera allows remote attackers to execute arbitrary code via a long URL in the first ar | 36.3% | — |
| CVE-2013-3908 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 6 through 10 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information from any visited document via a crafted web page that is not properly handled during a print-preview action, aka "I | 36.3% | — |
| CVE-2024-43464 | HIGH 7.2 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 36.3% | — |
| CVE-2022-37974 | MED 6.5 | microsoft windows_10 Windows Mixed Reality Developer Tools Information Disclosure Vulnerability | 36.3% | — |
| CVE-2008-1457 | HIGH 9.0 | microsoft windows-nt The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted even | 36.3% | — |
| CVE-2007-3895 | HIGH 9.3 | microsoft directx Buffer overflow in Microsoft DirectShow in Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted (1) WAV or (2) AVI file. | 36.2% | — |
| CVE-2019-1311 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'. | 36.2% | — |
| CVE-2007-2581 | MED 4.3 | microsoft sharepoint_server Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every | 36.2% | — |
| CVE-2007-2884 | HIGH 9.3 | microsoft visual_basic Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Nam | 36.2% | — |
| CVE-2003-0231 | MED 5.0 | microsoft data_engine Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe. | 36.2% | — |
| CVE-2022-22950 | MED 6.5 | vmware spring_framework n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition. | 36.1% | — |
| CVE-2002-1182 | MED 5.0 | microsoft internet_information_services IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned. | 36.1% | — |
| CVE-2007-0064 | HIGH 9.3 | microsoft windows_media_format_runtime Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Adv | 36.0% | — |
| CVE-2008-5518 | HIGH 9.4 | apache geronimo Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group | 35.9% | — |
| CVE-2016-3092 | HIGH 7.5 | apache commons_fileupload The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consum | 35.9% | — |
| CVE-2009-1131 | HIGH 9.3 | microsoft office_powerpoint Multiple stack-based buffer overflows in Microsoft Office PowerPoint 2000 SP3 allow remote attackers to execute arbitrary code via a large amount of data associated with unspecified atoms in a PowerPoint file that triggers memory corruption, aka "Data Out of B | 35.9% | — |
| CVE-2008-3021 | HIGH 9.3 | microsoft office Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file with an invalid bits_per_pixel field, aka the " | 35.9% | — |
| CVE-2000-0097 | MED 5.0 | microsoft index_server The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability. | 35.9% | — |
| CVE-2012-5975 | HIGH 9.3 | ssh tectia_server The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 through 6.3.2 on UNIX and Linux, when old-style password authentication is enabled, allows remote attackers to bypass authen | 35.9% | — |
| CVE-2024-38071 | HIGH 7.5 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Denial of Service Vulnerability | 35.9% | — |
| CVE-2006-5162 | MED 5.0 | microsoft internet_explorer wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) via a long Content-Type header, which triggers a stack overflow. | 35.8% | — |
| CVE-2017-0266 | HIGH 7.5 | microsoft edge A remote code execution vulnerability exists in Microsoft Edge in the way affected Microsoft scripting engines render when handling objects in memory, aka "Microsoft Edge Remote Code Execution Vulnerability." | 35.8% | — |
| CVE-2009-3135 | HIGH 9.3 | microsoft office Stack-based buffer overflow in Microsoft Office Word 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, Office Word Viewer 2003 SP3, and Office Word Viewer allow remote attackers to execute arbitrary code via a Word do | 35.8% | — |
| CVE-2007-1658 | HIGH 9.3 | microsoft windows_vista Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a link to a (1) local file or (2) UNC share pathname in which there is a directory with the same base name as an executable program at the same l | 35.8% | — |