IT

CVE Tracker

56.560 CVE

CVE-1999-0980
Medium 5.0

Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request.

microsoft windows_nt
0.23EPSS
CVE-2008-0639
High 10.0

Stack-based buffer overflow in the EnumPrinters function in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2, SP3, and SP4 for Windows allows remote attackers to execute arbitrary code via a crafted RPC request, aka Novell bug 353138, a different vu…

novell client
0.23EPSS
CVE-2005-0562
High 7.5

GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width.

microsoft msn_messenger
0.23EPSS
CVE-2018-4934
Medium 6.5

Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

adobe flash_player · adobe flash_player_desktop_runtime
0.23EPSS
CVE-2009-1287
Medium 4.3

Cross-site scripting (XSS) vulnerability in Cisco Subscriber Edge Services Manager (SESM) allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: some of these details are obtained from third party information.

cisco subscriber_edge_services_manager
0.23EPSS
CVE-2011-3406
High 8.8

Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1,…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.23EPSS
CVE-2015-1649
High 9.3

Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps Server 2010 SP2 allows remote attackers to execute …

microsoft office · microsoft office_compatibility_pack · microsoft office_web_apps · microsoft sharepoint_server · and 2 more
0.23EPSS
CVE-2017-8502
High 7.8

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8501.

microsoft excel
0.23EPSS
CVE-2006-2094
Medium 5.1

Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which…

microsoft ie · microsoft internet_explorer
0.23EPSS
CVE-2000-0028
Low 2.6

Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.

microsoft ie · microsoft internet_explorer
0.23EPSS
CVE-2017-8718
High 7.8

The Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to take control of an affected system, due…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.23EPSS
CVE-2025-57738
High 7.2

Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being p…

apache syncope
0.23EPSS
CVE-2019-0940
High 7.5

A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.

microsoft edge · microsoft internet_explorer
0.23EPSS
CVE-2010-0261
High 9.3

Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET rec…

microsoft excel · microsoft office · microsoft office_compatibility_pack · microsoft office_excel_viewer · and 2 more
0.23EPSS
CVE-2010-0260
High 9.3

Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted …

microsoft excel · microsoft office · microsoft office_compatibility_pack · microsoft office_excel_viewer · and 2 more
0.23EPSS
CVE-2018-8225
High 8.1

A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_server_2008 · and 2 more
0.23EPSS
CVE-2022-22957
High 7.2

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malici…

vmware cloud_foundation · vmware identity_manager · vmware vrealize_automation · vmware vrealize_suite_lifecycle_manager · and 1 more
0.23EPSS
CVE-2012-1863
Medium 4.3

Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScri…

microsoft office_sharepoint_server · microsoft sharepoint_foundation · microsoft sharepoint_server · microsoft sharepoint_services
0.23EPSS
CVE-2012-1859
Medium 4.3

Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via craf…

microsoft office_web_apps · microsoft sharepoint_foundation · microsoft sharepoint_server
0.23EPSS
CVE-2024-24549
High 7.5

Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after a…

apache tomcat · debian debian_linux · fedoraproject fedora
0.23EPSS
CVE-2002-20001
High 7.5

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. …

balasys dheater · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · and 26 more
0.23EPSS
CVE-2026-39813
Critical 9.8

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.

fortinet fortisandbox
0.23EPSS
CVE-2020-3249
High 7.5

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne…

cisco ucs_director · cisco ucs_director_express_for_big_data
0.23EPSS
CVE-1999-1223
Medium 5.0

IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.

microsoft internet_information_server
0.23EPSS
CVE-2016-3260
High 8.8

The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a…

microsoft edge · microsoft internet_explorer
0.23EPSS