56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.742 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-8739 | MED 4.3 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's system, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulner | 5.9% | — |
| CVE-2018-16044 | HIGH 8.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a secu | 5.9% | — |
| CVE-2010-0528 | HIGH 9.3 | apple quicktime Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted color tables in a movie file, related to malformed MediaVideo data, a sample descriptio | 5.9% | — |
| CVE-2007-4723 | HIGH 7.5 | ragnarok_online_control_panel_project ragnarok_online_control_panel Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as | 5.9% | — |
| CVE-2020-1232 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'. | 5.9% | — |
| CVE-2013-1845 | LOW 2.1 | apache subversion The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (memory consumption) by (1) setting or (2) deleting a large number of properties for a file or d | 5.9% | — |
| CVE-1999-0229 | MED 5.0 | microsoft internet_information_server Denial of service in Windows NT IIS server using ..\.. | 5.9% | — |
| CVE-1999-0274 | MED 5.0 | microsoft windows_nt Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made. | 5.9% | — |
| CVE-2022-2588 | MED 5.3 | canonical ubuntu_linux It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0. | 5.9% | — |
| CVE-2001-1288 | LOW 2.1 | microsoft windows_2000 Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt and pressing the F7 and enter keys several times while the command is executing, possibly related to an exception handling error i | 5.9% | — |
| CVE-2018-18865 | HIGH 8.1 | royalapplications royal_ts The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13) allow Credentials Disclosure. | 5.9% | — |
| CVE-2019-1238 | MED 6.4 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1239. | 5.9% | — |
| CVE-2017-5643 | HIGH 7.4 | apache camel Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE. | 5.9% | — |
| CVE-2015-6676 | HIGH 10.0 | adobe air Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attacke | 5.9% | — |
| CVE-2006-4950 | HIGH 10.0 | cisco ios Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOCSIS, which | 5.9% | — |
| CVE-2020-1416 | HIGH 8.8 | microsoft azure_storage_explorer An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'. | 5.9% | — |
| CVE-2010-3824 | HIGH 9.3 | apple safari Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors inv | 5.9% | — |
| CVE-2010-3805 | HIGH 9.3 | apple safari Integer underflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving WebS | 5.9% | — |
| CVE-2002-2379 | HIGH 7.8 | cisco as5350 Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a denial of service (crash) via a port scan, possibly due to an ssh bug. NOTE: this issue could not be reproduced by the vendor | 5.9% | — |
| CVE-2024-30084 | HIGH 7.0 | microsoft windows_10_1507 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 5.9% | — |
| CVE-2014-0525 | HIGH 10.0 | adobe acrobat The API in Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X does not prevent access to unmapped memory, which allows attackers to execute arbitrary code via unspecified API calls. | 5.9% | — |
| CVE-2021-44742 | LOW 3.3 | adobe acrobat Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory st | 5.9% | — |
| CVE-2017-6683 | HIGH 8.8 | cisco elastic_services_controller A vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to execute arbitrary commands as the tomcat user on an affected system, aka an Authentication Request Processing Arbitrary Command | 5.9% | — |
| CVE-2016-7881 | HIGH 8.8 | adobe flash_player Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the MovieClip class when handling conversion to an object. Successful exploitation could lead to arbitrary code execution. | 5.9% | — |
| CVE-2007-0711 | HIGH 9.3 | apple quicktime Integer overflow in Apple QuickTime before 7.1.5, when installed on Windows operating systems, allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP video file. | 5.9% | — |