56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.793 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2011-0623 | HIGH 9.3 | adobe flash_player Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code via unspecified vectors, related to a "bounds checking" issue, a different vulnerability than CVE-2011-0 | 4.9% | — |
| CVE-2011-0618 | HIGH 9.3 | adobe flash_player Integer overflow in Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code via unspecified vectors. | 4.9% | — |
| CVE-2005-4269 | HIGH 7.8 | microsoft ie mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Micro | 4.9% | — |
| CVE-2020-3218 | HIGH 7.2 | cisco ios_xe A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code with root privileges on the underlying Linux shell. The vulnerability is due to improper validation of | 4.9% | — |
| CVE-2018-14613 | MED 5.5 | linux linux_kernel An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in io_ctl_map_page() when mounting and operating a crafted btrfs image, because of a lack of block group item validation in check_leaf_item in fs/btrfs/tree-ch | 4.9% | — |
| CVE-2016-4188 | HIGH 8.8 | adobe flash_player Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different v | 4.9% | — |
| CVE-2008-2136 | HIGH 7.8 | canonical ubuntu_linux Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT) tunnel i | 4.9% | — |
| CVE-2009-2196 | MED 5.0 | apple mac_os_x Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors. | 4.9% | — |
| CVE-2001-1563 | HIGH 7.5 | apache tomcat Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers. | 4.9% | — |
| CVE-2017-15940 | CRIT 9.8 | paloaltonetworks pan-os The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors. | 4.9% | — |
| CVE-2020-1585 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install program | 4.9% | — |
| CVE-2018-17196 | HIGH 8.8 | apache kafka In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vul | 4.9% | — |
| CVE-2023-36439 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 4.9% | — |
| CVE-2010-2990 | HIGH 9.3 | citrix ica_client_for_linux Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobi | 4.9% | — |
| CVE-2025-29794 | HIGH 8.8 | microsoft sharepoint_enterprise_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 4.9% | — |
| CVE-2020-24410 | HIGH 7.8 | adobe illustrator Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing crafted PDF files. This could result in a read past the end of an allocated memory structure, potentially resulting in arbitrary code execution in the | 4.9% | — |
| CVE-2020-24409 | HIGH 7.8 | adobe illustrator Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing crafted PDF files. This could result in a read past the end of an allocated memory structure, potentially resulting in arbitrary code execution in the | 4.9% | — |
| CVE-2019-7815 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20091 and earlier, 2019.010.20091 and earlier, 2017.011.30120 and earlier version, and 2015.006.30475 and earlier have a data leakage (sensitive) vulnerability. Successful exploitation could lead to information disclo | 4.9% | — |
| CVE-1999-0576 | HIGH 7.5 | microsoft windows_nt A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories. | 4.9% | — |
| CVE-2022-20711 | CRIT 10.0 | cisco rv340_firmware Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot | 4.9% | — |
| CVE-2012-4446 | MED 6.8 | apache qpid The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via | 4.9% | — |
| CVE-2021-1723 | HIGH 7.5 | fedoraproject fedora ASP.NET Core and Visual Studio Denial of Service Vulnerability | 4.9% | — |
| CVE-2023-44371 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in | 4.9% | — |
| CVE-2022-47941 | HIGH 7.5 | linux linux_kernel An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions, aka a memory leak. | 4.9% | — |
| CVE-2020-1583 | HIGH 8.8 | microsoft 365_apps An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, a | 4.9% | — |