56.625 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.625 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-10883 | CRIT 9.8 | citrix citrix_sd-wan_center Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection. | 65.5% | — |
| CVE-2019-1072 | CRIT 9.8 | microsoft azure_devops_server A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'. | 12.4% | — |
| CVE-2019-10211 | CRIT 9.8 | postgresql postgresql Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory. | 1.8% | — |
| CVE-2019-10126 | CRIT 9.8 | canonical ubuntu_linux A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences. | 6.8% | — |
| CVE-2019-10125 | CRIT 9.8 | linux linux_kernel An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_wake() if an expected event is triggered immediately (e.g., by the close of a pair of pipes) after the return of vfs_poll(), and this will c | 5.3% | — |
| CVE-2019-10095 | CRIT 9.8 | apache zeppelin bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions. | 5.7% | — |
| CVE-2019-10074 | CRIT 9.8 | apache ofbiz An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be di | 3.4% | — |
| CVE-2019-10071 | CRIT 9.8 | apache tapestry The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the HMAC signatures. This could lead to remote code execution if an attacker is able to determine the correct sign | 8.8% | — |
| CVE-2019-0813 | CRIT 9.8 | microsoft windows_admin_center An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations, aka 'Windows Admin Center Elevation of Privilege Vulnerability'. | 3.5% | — |
| CVE-2019-0786 | CRIT 9.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server when an attacker with valid credentials attempts to open a specially crafted file over the SMB protocol on the same machine, aka 'SMB Server Elevation of Privileg | 7.0% | — |
| CVE-2019-0785 | CRIT 9.8 | microsoft windows_server_2012 A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'. | 49.6% | — |
| CVE-2019-0736 | CRIT 9.8 | microsoft windows_10 A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine. To exploit the vul | 4.0% | — |
| CVE-2019-0729 | CRIT 9.8 | microsoft java_software_development_kit An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'. | 3.1% | — |
| CVE-2019-0726 | CRIT 9.8 | microsoft windows_10 A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0697, CVE-2019-0698. | 54.0% | — |
| CVE-2019-0725 | CRIT 9.8 | microsoft windows_server_2008 A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'. | 26.3% | — |
| CVE-2019-0708 | CRIT 9.8 | ransomware huawei agile_controller-campus_firmware A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code | 100.0% | |
| CVE-2019-0698 | CRIT 9.8 | microsoft windows_10 A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0697, CVE-2019-0726. | 62.8% | — |
| CVE-2019-0697 | CRIT 9.8 | microsoft windows_10 A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726. | 29.6% | — |
| CVE-2019-0626 | CRIT 9.8 | microsoft windows_10 A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'. | 68.3% | — |
| CVE-2019-0604 | CRIT 9.8 | ransomware microsoft sharepoint_enterprise_server A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594. | 99.8% | |
| CVE-2019-0586 | CRIT 9.8 | microsoft exchange_server A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. | 15.4% | — |
| CVE-2019-0547 | CRIT 9.8 | microsoft windows_10 A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Client Remote Code Execution Vulnerability." This affects Windows 10, Windows 10 Servers. | 71.4% | — |
| CVE-2019-0230 | CRIT 9.8 | apache struts Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. | 97.1% | — |
| CVE-2019-0228 | CRIT 9.8 | apache james Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF. | 9.5% | — |
| CVE-2019-0219 | CRIT 9.8 | apache cordova_inappbrowser A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI. | 7.8% | — |