56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.793 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-0587 | HIGH 10.0 | adobe flash_player Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different v | 4.5% | — |
| CVE-2020-4207 | CRIT 9.8 | ibm iot_messagesight IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when handling a failed HTTP request with specific content in the headers. By sending a specially crafted HTTP request, | 4.5% | — |
| CVE-2024-30032 | HIGH 7.8 | microsoft windows_10_1507 Windows DWM Core Library Elevation of Privilege Vulnerability | 4.5% | — |
| CVE-2011-3248 | HIGH 9.3 | apple quicktime Integer signedness error in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font table in a QuickTime movie file. | 4.5% | — |
| CVE-2021-1294 | CRIT 9.8 | cisco rv160_vpn_router_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These | 4.5% | — |
| CVE-2019-1125 | MED 5.6 | microsoft windows_10 An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, | 4.5% | — |
| CVE-2010-2217 | HIGH 10.0 | adobe flash_media_server Adobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows attackers to execute arbitrary code via unspecified vectors, related to a "JS method vulnerability." | 4.5% | — |
| CVE-2021-31965 | MED 5.7 | microsoft sharepoint_foundation Microsoft SharePoint Server Information Disclosure Vulnerability | 4.5% | — |
| CVE-2010-0008 | HIGH 7.8 | linux linux_kernel The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause a denial of service (infinite loop) via (1) an Out Of The Blue (OOTB) chunk or (2) a chunk of zero length. | 4.5% | — |
| CVE-2019-6754 | HIGH 7.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.3.10826. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 4.5% | — |
| CVE-2014-8709 | MED 5.0 | linux linux_kernel The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allows remote attackers to obtain sensitive cleartext information by reading packets. | 4.5% | — |
| CVE-2024-38100 | HIGH 7.8 | microsoft windows_server_2016 Windows File Explorer Elevation of Privilege Vulnerability | 4.5% | — |
| CVE-2017-12544 | MED 5.4 | hp system_management_homepage A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. | 4.5% | — |
| CVE-2003-0043 | MED 5.0 | apache tomcat Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file. | 4.5% | — |
| CVE-2011-0450 | HIGH 7.6 | opera opera_browser The downloads manager in Opera before 11.01 on Windows does not properly determine the pathname of the filesystem-viewing application, which allows user-assisted remote attackers to execute arbitrary code via a crafted web site that hosts an executable file. | 4.5% | — |
| CVE-2020-1940 | HIGH 7.5 | apache jackrabbit_oak The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates the changed password to be passed as an additional attribute | 4.5% | — |
| CVE-2018-0279 | HIGH 8.8 | cisco enterprise_nfv_infrastructure_software A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerabilit | 4.5% | — |
| CVE-2020-1555 | HIGH 8.8 | microsoft chakracore A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the | 4.5% | — |
| CVE-2024-21408 | MED 5.5 | microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability | 4.5% | — |
| CVE-2012-1910 | HIGH 7.5 | bitcoin bitcoin-qt Bitcoin-Qt 0.5.0.x before 0.5.0.5; 0.5.1.x, 0.5.2.x, and 0.5.3.x before 0.5.3.1; and 0.6.x before 0.6.0rc4 on Windows does not use MinGW multithread-safe exception handling, which allows remote attackers to cause a denial of service (application crash) or poss | 4.5% | — |
| CVE-2020-8983 | HIGH 7.5 | citrix sharefile_storagezones_controller An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, which allows remote code execution. RCE and file access is granted to everything hos | 4.5% | — |
| CVE-2020-13143 | MED 6.5 | canonical ubuntu_linux gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4. | 4.5% | — |
| CVE-2018-10938 | MED 5.9 | canonical ubuntu_linux A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a deni | 4.5% | — |
| CVE-2018-1313 | MED 5.3 | apache derby In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. If the Derby Network Server is not running with a Java Securi | 4.5% | — |
| CVE-2018-0238 | CRIT 9.9 | cisco unified_computing_system_director A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in the UCS Director end-user portal an | 4.5% | — |