56.794 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.794 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-0596 | HIGH 7.8 | microsoft visual_studio_community Untrusted search path vulnerability in the installer of Visual Studio Community allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 4.4% | — |
| CVE-2018-0595 | HIGH 7.8 | microsoft skype Untrusted search path vulnerability in the installer of Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 4.4% | — |
| CVE-2018-0594 | HIGH 7.8 | microsoft skype Untrusted search path vulnerability in Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 4.4% | — |
| CVE-2018-0593 | HIGH 7.8 | microsoft onedrive Untrusted search path vulnerability in the installer of Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 4.4% | — |
| CVE-2018-0592 | HIGH 7.8 | microsoft onedrive Untrusted search path vulnerability in Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 4.4% | — |
| CVE-2019-1861 | HIGH 7.2 | cisco industrial_network_director A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of files uploaded to the affected application. An attac | 4.4% | — |
| CVE-2011-1797 | HIGH 9.3 | apple safari WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2 | 4.4% | — |
| CVE-2007-1915 | HIGH 7.5 | sap rfc_library Buffer overflow in the RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be | 4.4% | — |
| CVE-2003-0982 | HIGH 7.5 | cisco application_and_content_networking_software Buffer overflow in the authentication module for Cisco ACNS 4.x before 4.2.11, and 5.x before 5.0.5, allows remote attackers to execute arbitrary code via a long password. | 4.4% | — |
| CVE-2023-38143 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 4.4% | — |
| CVE-2021-28610 | HIGH 7.8 | adobe after_effects Adobe After Effects version 18.2 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of | 4.4% | — |
| CVE-2007-2461 | HIGH 7.8 | cisco adaptive_security_appliance_software The DHCP relay agent in Cisco Adaptive Security Appliance (ASA) and PIX 7.2 allows remote attackers to cause a denial of service (dropped packets) via a DHCPREQUEST or DHCPINFORM message that causes multiple DHCPACK messages to be sent from DHCP servers to the | 4.4% | — |
| CVE-2019-8047 | CRIT 9.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploi | 4.4% | — |
| CVE-2019-8025 | CRIT 9.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploi | 4.4% | — |
| CVE-2016-1112 | CRIT 9.8 | adobe acrobat Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to obtain sensitive information via unspecified vectors. | 4.4% | — |
| CVE-2018-12368 | HIGH 8.1 | mozilla firefox Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and have the "Mark of the Web." Without the warning, unsuspecting users unfamiliar with this new file type | 4.4% | — |
| CVE-2018-1331 | HIGH 8.8 | apache storm In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user. | 4.4% | — |
| CVE-2024-20755 | HIGH 7.8 | adobe bridge Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o | 4.4% | — |
| CVE-2022-35691 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the c | 4.4% | — |
| CVE-2020-16856 | HIGH 7.8 | microsoft visual_studio <p>A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged o | 4.4% | — |
| CVE-2018-0016 | CRIT 9.8 | juniper junos Receipt of a specially crafted Connectionless Network Protocol (CLNP) datagram destined to an interface of a Junos OS device may result in a kernel crash or lead to remote code execution. Devices are only vulnerable to the specially crafted CLNP datagram if 'c | 4.4% | — |
| CVE-2011-1770 | HIGH 7.5 | fedoraproject fedora Integer underflow in the dccp_parse_options function (net/dccp/options.c) in the Linux kernel before 2.6.33.14 allows remote attackers to cause a denial of service via a Datagram Congestion Control Protocol (DCCP) packet with an invalid feature options length, | 4.4% | — |
| CVE-2000-0767 | LOW 2.6 | microsoft internet_explorer The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability. | 4.4% | — |
| CVE-2020-1217 | HIGH 7.8 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Information Disclosure Vulnerability'. | 4.4% | — |
| CVE-2019-18197 | HIGH 7.5 | canonical ubuntu_linux In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written t | 4.4% | — |