57.638 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.638 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-37382 | MED 5.5 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 0.9% | — |
| CVE-2022-37380 | MED 5.5 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 0.9% | — |
| CVE-2022-37379 | MED 5.5 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 0.9% | — |
| CVE-2022-38745 | HIGH 7.8 | apache openoffice Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory. | 0.9% | — |
| CVE-2022-34705 | HIGH 7.8 | microsoft windows_10 Windows Defender Credential Guard Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-36938 | MED 5.5 | microsoft windows_10 Windows Cryptographic Primitives Library Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-34457 | MED 5.5 | microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-34454 | MED 5.5 | microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-34440 | MED 5.5 | microsoft windows_10 GDI+ Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-33763 | MED 5.5 | microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.9% | — |
| CVE-2020-26558 | MED 4.2 | bluetooth bluetooth_core_specification Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the | 0.9% | — |
| CVE-2018-21032 | MED 4.3 | hitachi automation_director A vulnerability in Hitachi Command Suite prior to 8.7.1-00 and Hitachi Automation Director prior to 8.5.0-00 allow authenticated remote users to expose technical information through error messages. Hitachi Command Suite includes Hitachi Device Manager and Hita | 0.9% | — |
| CVE-2019-6664 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 15.0.0 and 14.1.0-14.1.0.6, under certain conditions, network protections on the management port do not follow current best practices. | 0.9% | — |
| CVE-2017-0535 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the HTC sound codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produ | 0.9% | — |
| CVE-2006-3547 | MED 5.5 | vmware player EMC VMware Player allows user-assisted attackers to cause a denial of service (unrecoverable application failure) via a long value of the ide1:0.fileName parameter in the .vmx file of a virtual machine. NOTE: third parties have disputed this issue, saying tha | 0.9% | — |
| CVE-2026-45639 | HIGH 7.5 | microsoft remote_desktop_client Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-42908 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2024-42145 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: IB/core: Implement a limit on UMAD receive List The existing behavior of ib_umad, which maintains received MAD packets in an unbounded list, poses a risk of uncontrolled growth. As user-spac | 0.9% | — |
| CVE-2023-5727 | MED 6.5 | mozilla firefox The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* | 0.9% | — |
| CVE-2023-23384 | HIGH 7.3 | microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2020-0805 | MED 5.3 | microsoft windows_10 <p>A security feature bypass vulnerability exists when a Windows Projected Filesystem improperly handles file redirections. An attacker who successfully exploited this vulnerability could delete a targeted file they would not have permissions to.</p> <p>To exp | 0.9% | — |
| CVE-2020-2033 | MED 5.3 | paloaltonetworks globalprotect When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with the ability to manipu | 0.9% | — |
| CVE-2020-1014 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'Microsoft Windows Update Client Elevation of Privilege Vulnerability'. | 0.9% | — |
| CVE-2018-11805 | MED 6.7 | apache spamassassin In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should on | 0.9% | — |
| CVE-2019-1568 | MED 6.1 | paloaltonetworks demisto Cross-site scripting (XSS) vulnerability in Palo Alto Networks Demisto 4.5 build 40249 may allow an unauthenticated attacker to run arbitrary JavaScript or HTML. | 0.9% | — |