58.165 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-16860 | HIGH 7.3 | code42 code42 Code42 app through version 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local machine could create or modify a dynamic-link library (DLL). The Code42 service could then load it at runtime, and pote | 0.4% | — |
| CVE-2019-1317 | HIGH 7.3 | microsoft windows_10 A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'. | 1.0% | — |
| CVE-2019-1211 | HIGH 7.3 | microsoft visual_studio_2017 An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. An attacker who successfully exploited the vulnerability could execute code in the context of another local user. To exploit the vulnerabilit | 1.7% | — |
| CVE-2019-1185 | HIGH 7.3 | microsoft windows_10 An elevation of privilege vulnerability exists due to a stack corruption in Windows Subsystem for Linux. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticate | 1.1% | — |
| CVE-2019-11272 | HIGH 7.3 | debian debian_linux Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a nul | 1.4% | — |
| CVE-2019-10086 | HIGH 7.3 | apache commons_beanutils In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default charac | 29.2% | — |
| CVE-2018-3962 | HIGH 7.3 | foxitsoftware phantompdf A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the CreationDate property of the this.info object. An attacker needs to trick the user t | 2.5% | — |
| CVE-2018-18999 | HIGH 7.3 | advantech webaccess\/scada WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user supplied input may allow an attacker to cause the overflow of a buffer on the stack. | 2.3% | — |
| CVE-2018-18098 | HIGH 7.3 | intel sgx_platform_software Improper file verification in install routine for Intel(R) SGX SDK and Platform Software for Windows before 2.2.100 may allow an escalation of privilege via local access. | 0.3% | — |
| CVE-2018-15431 | HIGH 7.3 | cisco webex_business_suite_32 A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 0.5% | — |
| CVE-2018-10877 | HIGH 7.3 | canonical ubuntu_linux Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating on a crafted ext4 filesystem image. | 2.2% | — |
| CVE-2018-0422 | HIGH 7.3 | cisco webex_business_suite_31 A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally stored files and execute code on a targeted device with the privilege level of the user. The vulnerability is du | 1.1% | — |
| CVE-2018-0181 | HIGH 7.3 | cisco cisco_policy_suite_diameter_routing_agent A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software could allow an unauthenticated, remote attacker to modify key-value pairs for short-lived events stored by the Redis se | 2.2% | — |
| CVE-2017-8494 | HIGH 7.3 | microsoft windows_10 Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a locally-authenticated attacker to run a specially crafted application on a targeted system when Windows Secure Kernel Mode fails to properly handle objects in memory, aka "Windows | 1.9% | — |
| CVE-2017-8460 | HIGH 7.3 | microsoft windows_10 Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows information disclosure when a user opens a specially crafted PDF file, aka "Windows PDF Information Disclosure Vulner | 3.3% | — |
| CVE-2017-6543 | HIGH 7.3 | tenable appliance Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subseque | 0.8% | — |
| CVE-2017-6145 | HIGH 7.3 | f5 big-ip_access_policy_manager iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.0.0 through 12.1.2 and 13.0.0 includes a service to convert authorization BIGIPAuthCookie cookies to X-F5-Auth-Token tokens. This service does not properly | 1.1% | — |
| CVE-2017-5662 | HIGH 7.3 | apache batik In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application | 4.1% | — |
| CVE-2017-5661 | HIGH 7.3 | apache formatting_objects_processor In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is r | 2.5% | — |
| CVE-2017-3162 | HIGH 7.3 | apache hadoop HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validated in Apache Hadoop before 2.7.0. | 6.3% | — |
| CVE-2017-2331 | HIGH 7.3 | juniper northstar_controller A firewall bypass vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to bypass firewall policies, leading to authentication bypass methods, information disclosur | 1.1% | — |
| CVE-2017-1297 | HIGH 7.3 | ibm data_server_client IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159. | 1.5% | — |
| CVE-2017-0298 | HIGH 7.3 | microsoft windows_10 A DCOM object in Helppane.exe in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016, when configured to run as the interactive us | 1.9% | — |
| CVE-2017-0249 | HIGH 7.3 | microsoft asp.net_model_view_controller An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | 4.2% | — |
| CVE-2017-0213 | HIGH 7.3 | ransomware microsoft windows_10_1507 Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerabi | 84.1% |