56.775 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.775 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-41103 | CRIT 9.1 | microsoft confluence_saml_sso Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. | 5.4% | — |
| CVE-2017-8569 | HIGH 8.8 | microsoft sharepoint_server Microsoft SharePoint Server allows an elevation of privilege vulnerability due to the way that it sanitizes a specially crafted web request to an affected SharePoint server, aka "SharePoint Server XSS Vulnerability". | 5.4% | — |
| CVE-2019-19052 | HIGH 7.5 | broadcom brocade_fabric_operating_system_firmware A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486. | 5.4% | — |
| CVE-2006-5913 | MED 6.4 | microsoft ie Microsoft Internet Explorer 7 allows remote attackers to (1) cause a security certificate from a secure web site to appear invalid via a link to res://ieframe.dll/sslnavcancel.htm with the target site in the anchor identifier, which displays the site's URL in | 5.4% | — |
| CVE-2023-20178 | HIGH 7.8 | cisco anyconnect_secure_mobility_client A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The | 5.4% | — |
| CVE-2020-1382 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1381. | 5.4% | — |
| CVE-2007-6286 | MED 4.3 | apache tomcat Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests | 5.4% | — |
| CVE-2018-8024 | MED 5.4 | apache spark In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to ex | 5.4% | — |
| CVE-2021-21090 | HIGH 8.8 | adobe incopy Adobe InCopy version 16.0 (and earlier) is affected by an path traversal vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation | 5.4% | — |
| CVE-2019-1443 | MED 6.5 | microsoft sharepoint_enterprise_server An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint func | 5.4% | — |
| CVE-2012-1089 | MED 5.0 | apache wicket Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package. | 5.4% | — |
| CVE-2002-0886 | MED 5.0 | cisco cbos Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large packet to the DHCP port, (2) a large packet to the Telnet port, or (3) a flood of large packets to the CPE, w | 5.4% | — |
| CVE-2001-1064 | MED 5.0 | cisco cbos Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding pa | 5.4% | — |
| CVE-2016-1111 | HIGH 8.8 | adobe acrobat Double free vulnerability in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allows attackers to execute arbitrary code via | 5.4% | — |
| CVE-2020-16881 | HIGH 7.8 | microsoft visual_studio_code <p>A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'package.json' file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If | 5.4% | — |
| CVE-2021-29943 | CRIT 9.1 | apache solr When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization reso | 5.4% | — |
| CVE-2014-0565 | HIGH 10.0 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0566. | 5.4% | — |
| CVE-2014-9428 | HIGH 7.8 | linux linux_kernel The batadv_frag_merge_packets function in net/batman-adv/fragmentation.c in the B.A.T.M.A.N. implementation in the Linux kernel through 3.18.1 uses an incorrect length field during a calculation of an amount of memory, which allows remote attackers to cause a | 5.4% | — |
| CVE-2010-1750 | HIGH 9.3 | apple safari Use-after-free vulnerability in Apple Safari before 5.0 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to improper window management. | 5.4% | — |
| CVE-2008-0530 | HIGH 10.0 | cisco session_initiation_protocol_\(sip\)_firmware Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP and SIP firmware might allow remote attackers to execute arbitrary code via a crafted DNS response. | 5.4% | — |
| CVE-2008-0529 | HIGH 10.0 | cisco session_initiation_protocol_\(sip\)_firmware Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted command. | 5.4% | — |
| CVE-2008-0528 | HIGH 10.0 | cisco session_initiation_protocol_\(sip\)_firmware Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote attackers to execute arbitrary code via a SIP message with crafted MIME data. | 5.4% | — |
| CVE-2008-0766 | HIGH 10.0 | brooks_internet_software rpm_remote_print_manager_elite Stack-based buffer overflow in RpmSrvc.exe in Brooks Remote Print Manager (RPM) 4.5.1.11 and earlier (Elite and Select) for Windows allows remote attackers to execute arbitrary code via a long filename in a "Receive data file" LPD command. NOTE: some of these | 5.4% | — |
| CVE-2005-3848 | HIGH 7.8 | linux linux_kernel Memory leak in the icmp_push_reply function in Linux 2.6 before 2.6.12.6 and 2.6.13 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted packets that cause the ip_append_data function to fail, aka "DST leak in | 5.4% | — |
| CVE-2023-38144 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 5.4% | — |