56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.571 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-1127 | MED 5.0 | microsoft internet_explorer Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript cod | 18.3% | — |
| CVE-2012-1873 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 7 through 9 does not properly create and initialize string data, which allows remote attackers to obtain sensitive information from process memory via a crafted HTML document, aka "Null Byte Information Disclosure Vulnerability." | 18.3% | — |
| CVE-2007-1858 | LOW 2.6 | apache tomcat The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have oth | 18.3% | — |
| CVE-2015-6107 | HIGH 9.3 | microsoft live_meeting The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10 Gold and 1511, Office 2007 SP3, Office 2010 SP2, Word Viewe | 18.2% | — |
| CVE-2006-0376 | HIGH 7.5 | microsoft windows_2000 The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc mode e | 18.2% | — |
| CVE-2006-3660 | HIGH 7.6 | microsoft powerpoint Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, an | 18.2% | — |
| CVE-2010-2563 | HIGH 9.3 | microsoft windows_server_2003 The Word 97 text converter in the WordPad Text Converters in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse malformed structures in Word 97 documents, which allows remote attackers to execute arbitrary code via a crafted document | 18.2% | — |
| CVE-2017-8509 | HIGH 8.8 | microsoft office A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8510, CVE-2017-8511, CVE-2017-8512, CVE-2017-02 | 18.2% | — |
| CVE-2015-2505 | MED 5.0 | microsoft exchange_server Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to obtain sensitive stacktrace information via a crafted request, aka "Exchange Information Disclosure Vulnerability." | 18.2% | — |
| CVE-2002-0052 | MED 5.0 | microsoft internet_explorer Internet Explorer 6.0 and earlier does not properly handle VBScript in certain domain security checks, which allows remote attackers to read arbitrary files. | 18.2% | — |
| CVE-2014-1811 | MED 5.0 | microsoft windows_7 The TCP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (non-paged pool | 18.2% | — |
| CVE-2007-1763 | HIGH 7.1 | microsoft windows_vista The ATI kernel driver (atikmdag.sys) in Microsoft Windows Vista allows user-assisted remote attackers to cause a denial of service (crash) via a crafted JPG image, as demonstrated by a slideshow, possibly due to a buffer overflow. | 18.2% | — |
| CVE-2017-2984 | HIGH 8.8 | adobe flash_player Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the h264 decoder routine. Successful exploitation could lead to arbitrary code execution. | 18.2% | — |
| CVE-1999-0385 | HIGH 10.0 | microsoft exchange_server The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. | 18.2% | — |
| CVE-2005-3774 | MED 5.0 | cisco pix Cisco PIX 6.3 and 7.0 allows remote attackers to cause a denial of service (blocked new connections) via spoofed TCP packets that cause the PIX to create embryonic connections that that would not produce a valid connection with the end system, including (1) SY | 18.2% | — |
| CVE-1999-0012 | HIGH 7.0 | microsoft frontpage Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names. | 18.2% | — |
| CVE-2001-0664 | HIGH 7.5 | microsoft internet_explorer Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, ak | 18.2% | — |
| CVE-2019-12624 | HIGH 8.8 | cisco ios_xe A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected d | 18.2% | — |
| CVE-2020-17096 | HIGH 7.5 | microsoft windows_10 Windows NTFS Remote Code Execution Vulnerability | 18.2% | — |
| CVE-2023-25610 | CRIT 9.8 | fortinet fortianalyzer A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2 | 18.2% | — |
| CVE-2015-0005 | MED 4.3 | microsoft windows_2003_server The NETLOGON service in Microsoft Windows Server 2003 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2, when a Domain Controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoint, and o | 18.2% | — |
| CVE-2025-49712 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 18.2% | — |
| CVE-2019-1373 | CRIT 9.8 | microsoft exchange_server A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'. | 18.2% | — |
| CVE-2018-8376 | HIGH 8.8 | microsoft powerpoint A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft PowerPoint. | 18.2% | — |
| CVE-2017-0196 | MED 6.5 | microsoft edge An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." | 18.2% | — |