56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.832 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2000-0162 | MED 5.1 | microsoft ie The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability. | 7.6% | — |
| CVE-2000-0156 | MED 5.1 | microsoft internet_explorer Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability. | 12.8% | — |
| CVE-1999-1578 | MED 5.1 | microsoft internet_explorer Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands. | 19.4% | — |
| CVE-1999-1577 | MED 5.1 | microsoft internet_explorer Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method. | 19.5% | — |
| CVE-1999-1575 | MED 5.1 | microsoft internet_explorer The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE Active | 35.6% | — |
| CVE-1999-1128 | MED 5.1 | microsoft internet_explorer Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user. | 3.6% | — |
| CVE-1999-1093 | MED 5.1 | microsoft internet_explorer Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page. | 12.6% | — |
| CVE-1999-0981 | MED 5.1 | microsoft internet_explorer Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect." | 13.1% | — |
| CVE-1999-0917 | MED 5.1 | microsoft internet_explorer The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files. | 6.2% | — |
| CVE-1999-0750 | MED 5.1 | microsoft hotmail Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account. | 8.7% | — |
| CVE-1999-0668 | MED 5.1 | microsoft internet_explorer The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. | 22.6% | — |
| CVE-1999-0061 | MED 5.1 | bsdi bsd_os File creation and deletion, and remote execution, in the BSD line printer daemon (lpd). | 2.5% | — |
| CVE-2026-33921 | MED 5.2 | The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privi | 0.1% | — |
| CVE-2025-5781 | MED 5.2 | hitachi configuration_manager Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; | 0.1% | — |
| CVE-2025-46707 | MED 5.2 | imaginationtech ddk Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU. | 0.1% | — |
| CVE-2025-22221 | MED 5.2 | vmware aria_operations_for_logs VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performin | 0.4% | — |
| CVE-2024-21337 | MED 5.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2021-36192 | MED 5.2 | fortinet fortimanager An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 7.0.1 and below, 6.4.6 and below, 6.2.x, 6.0.x, 5.6.0 may allow a FortiGate user to see scripts from other ADOMS. | 0.2% | — |
| CVE-2021-31201 | MED 5.2 | microsoft windows_10_1507 Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | 2.6% | |
| CVE-2021-31199 | MED 5.2 | microsoft windows_10_1507 Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | 3.0% | |
| CVE-2021-29827 | MED 5.2 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and | 0.3% | — |
| CVE-2021-21552 | MED 5.2 | microsoft windows_10 Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass the restricted environment and | 1.0% | — |
| CVE-2020-27223 | MED 5.2 | apache nifi In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due | 78.0% | — |
| CVE-2019-12703 | MED 5.2 | cisco spa122_firmware A vulnerability in the web-based management interface of Cisco SPA122 ATA with Router Devices could allow an unauthenticated, adjacent attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-supplied input | 0.4% | — |
| CVE-2014-0102 | MED 5.2 | linux linux_kernel The keyring_detect_cycle_iterator function in security/keys/keyring.c in the Linux kernel through 3.13.6 does not properly determine whether keyrings are identical, which allows local users to cause a denial of service (OOPS) via crafted keyctl commands. | 0.6% | — |