56.625 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.625 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-6044 | MED 6.8 | microsoft internet_explorer Microsoft Internet Explorer 8 allows remote attackers to gain privileges via a crafted web site, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Internet Explorer Elevation of Privilege Vulnerability." | 9.5% | — |
| CVE-2018-15756 | HIGH 7.5 | debian debian_linux Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starti | 9.5% | — |
| CVE-2017-11767 | CRIT 9.8 | microsoft chakracore ChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | 9.5% | — |
| CVE-2000-0768 | LOW 2.6 | microsoft ie A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability. | 9.5% | — |
| CVE-2017-3062 | CRIT 9.8 | adobe flash_player Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 when creating a getter/setter property. Successful exploitation could lead to arbitrary code execution. | 9.5% | — |
| CVE-2017-3059 | CRIT 9.8 | adobe flash_player Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the internal script object. Successful exploitation could lead to arbitrary code execution. | 9.5% | — |
| CVE-2013-1768 | HIGH 7.5 | apache openjpa The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attack | 9.5% | — |
| CVE-2002-2311 | MED 6.4 | microsoft internet_explorer Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was r | 9.5% | — |
| CVE-2024-30087 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 9.5% | — |
| CVE-2018-1311 | HIGH 8.1 | apache xerces-c\+\+ The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD proc | 9.5% | — |
| CVE-2019-1225 | HIGH 7.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the system. To exploit this vul | 9.5% | — |
| CVE-2017-7041 | HIGH 8.8 | apple icloud An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the | 9.5% | — |
| CVE-2017-8585 | HIGH 7.5 | microsoft .net_framework Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability. | 9.5% | — |
| CVE-2010-4180 | MED 4.3 | canonical ubuntu_linux OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended ciphe | 9.5% | — |
| CVE-2017-11884 | HIGH 7.8 | microsoft excel Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-118 | 9.5% | — |
| CVE-2021-25329 | HIGH 7.0 | apache tomcat The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE | 9.5% | — |
| CVE-2010-2119 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid nntp:// URIs. | 9.5% | — |
| CVE-2013-4590 | MED 4.3 | apache tomcat Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document co | 9.5% | — |
| CVE-2015-2544 | MED 4.3 | microsoft exchange_server Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, aka "Exchange Spoofing Vulnera | 9.5% | — |
| CVE-2015-2543 | MED 4.3 | microsoft exchange_server Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, aka "Exchange Spoofing Vulnerability." | 9.5% | — |
| CVE-2018-3964 | HIGH 7.8 | foxitsoftware phantompdf An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code exec | 9.5% | — |
| CVE-2007-3383 | MED 4.3 | apache tomcat Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the Fr | 9.5% | — |
| CVE-2022-24070 | HIGH 7.5 | apache subversion Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). | 9.5% | — |
| CVE-2013-1299 | MED 5.8 | microsoft modern_mail Microsoft Windows Modern Mail allows remote attackers to spoof link targets via a crafted HTML e-mail message. | 9.5% | — |
| CVE-2016-10277 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as Critical due to the possibility of a local permanent device com | 9.5% | — |