IT
57.436 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync

CVE Tracker

57.436 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2016-8444 HIGH 7.0 linux linux_kernel An elevation of privilege vulnerability in the Qualcomm camera could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Produ 1.4%
CVE-2011-1234 HIGH 7.2 microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain 1.4%
CVE-2022-37022 HIGH 8.8 apache geode Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user wishing to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode 1.15. U 1.4%
CVE-2021-44700 MED 5.5 adobe illustrator Adobe Illustrator versions 25.4.2 (and earlier) and 26.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex 1.4%
CVE-2019-1325 MED 5.5 microsoft windows_10 An elevation of privilege vulnerability exists in the Windows redirected drive buffering system (rdbss.sys) when the operating system improperly handles specific local calls within Windows 7 for 32-bit systems, aka 'Windows Redirected Drive Buffering System El 1.4%
CVE-2025-53805 HIGH 7.5 microsoft windows_11_22h2 Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network. 1.4%
CVE-2023-28254 HIGH 7.2 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 1.4%
CVE-2021-27077 HIGH 7.8 microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability 1.4%
CVE-2021-2018 HIGH 8.3 oracle adaptive_access_manager Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advan 1.4%
CVE-2021-1263 HIGH 7.8 cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more informa 1.4%
CVE-2020-1417 MED 5.5 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, 1.4%
CVE-2019-0620 HIGH 7.6 microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a 1.4%
CVE-2022-40954 MED 5.5 apache airflow Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to DAG files 1.4%
CVE-2021-36173 HIGH 8.0 fortinet fortios A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 may allow an attacker to execute arbitrary code via specially crafted installation 1.4%
CVE-2016-8393 HIGH 7.0 linux linux_kernel An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged p 1.4%
CVE-2012-0157 HIGH 8.4 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle window messaging, which allows local users to ga 1.4%
CVE-2006-7039 MED 5.0 atrium_software mercur_messaging_2005 The IMAP4 service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (crash) via a message with a long subject field. 1.4%
CVE-2023-39180 MED 4.0 linux linux_kernel A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of 1.4%
CVE-2023-35302 HIGH 8.8 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability 1.4%
CVE-2005-3753 HIGH 7.8 linux linux_kernel Linux kernel before after 2.6.12 and before 2.6.13.1 might allow attackers to cause a denial of service (Oops) via certain IPSec packets that cause alignment problems in standard multi-block cipher processors. NOTE: it is not clear whether this issue can be t 1.4%
CVE-2024-43447 HIGH 8.1 microsoft windows_server_2022 Windows SMBv3 Server Remote Code Execution Vulnerability 1.4%
CVE-2021-21706 MED 5.3 php php In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be 1.4%
CVE-2018-6980 HIGH 7.2 vmware vrealize_log_insight VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method. Successful exploitation of this issue may allow Admin users with view only permission to perform cer 1.4%
CVE-2018-4347 HIGH 7.8 apple icloud A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7. 1.4%
CVE-2019-1877 MED 6.5 cisco enterprise_chat_and_email A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through chat sessions. The vulnerability is due to insufficient authentication mechanisms on the file download functio 1.4%