56.707 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.707 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-5021 | CRIT 9.8 | f5 big-ip_controller Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using af | 6.3% | — |
| CVE-2017-2994 | HIGH 8.8 | adobe flash_player Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in Primetime SDK event dispatch. Successful exploitation could lead to arbitrary code execution. | 6.3% | — |
| CVE-2000-0439 | LOW 2.6 | microsoft internet_explorer Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability. | 6.3% | — |
| CVE-2015-7663 | HIGH 10.0 | adobe air Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 a | 6.3% | — |
| CVE-2006-2806 | HIGH 7.8 | apache james The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption) via a long argument to the MAIL command. | 6.3% | — |
| CVE-2019-12406 | MED 6.5 | apache cxf Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of me | 6.3% | — |
| CVE-2022-40146 | HIGH 7.5 | apache batik Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14. | 6.3% | — |
| CVE-2020-1108 | HIGH 7.5 | microsoft .net A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vuln | 6.3% | — |
| CVE-2021-38153 | MED 5.9 | apache kafka Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or highe | 6.3% | — |
| CVE-2017-13798 | HIGH 8.8 | apple icloud An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKi | 6.3% | — |
| CVE-2017-3162 | HIGH 7.3 | apache hadoop HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validated in Apache Hadoop before 2.7.0. | 6.3% | — |
| CVE-2023-35644 | HIGH 7.8 | microsoft windows_10_1809 Windows Sysmain Service Elevation of Privilege Vulnerability | 6.3% | — |
| CVE-2024-52316 | CRIT 9.8 | apache tomcat Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an | 6.2% | — |
| CVE-2016-6992 | HIGH 8.8 | adobe flash_player Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion." | 6.2% | — |
| CVE-2016-4974 | HIGH 7.5 | apache amqp_0-x_jms_client Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and ex | 6.2% | — |
| CVE-2015-5366 | MED 5.0 | linux linux_kernel The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 provide inappropriate -EAGAIN return values, which allows remote attackers to cause a denial of service (EPOLLET epoll application read outage) via an incorrect checksum in a | 6.2% | — |
| CVE-2001-0147 | HIGH 10.0 | microsoft windows_2000 Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records. | 6.2% | — |
| CVE-2022-21849 | CRIT 9.8 | microsoft windows_10 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | 6.2% | — |
| CVE-2019-1356 | MED 6.5 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'. | 6.2% | — |
| CVE-2017-16544 | HIGH 8.8 | busybox busybox In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This c | 6.2% | — |
| CVE-2017-2937 | HIGH 8.8 | adobe flash_player Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript FileReference class, when using class inheritance. Successful exploitation could lead to arbitrary code execution. | 6.2% | — |
| CVE-2017-2936 | HIGH 8.8 | adobe flash_player Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript FileReference class. Successful exploitation could lead to arbitrary code execution. | 6.2% | — |
| CVE-2019-17075 | HIGH 7.5 | linux linux_kernel An issue was discovered in write_tpt_entry in drivers/infiniband/hw/cxgb4/mem.c in the Linux kernel through 5.3.2. The cxgb4 driver is directly calling dma_map_single (a DMA function) from a stack variable. This could allow an attacker to trigger a Denial of S | 6.2% | — |
| CVE-2018-12828 | CRIT 9.8 | adobe flash_player Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successful exploitation could lead to privilege escalation. | 6.2% | — |
| CVE-2018-12825 | CRIT 9.8 | adobe flash_player Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to security mitigation bypass. | 6.2% | — |