IT
56.807 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.807 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-30618 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30618 Inappropriate implementation in DevTools 4.1%
CVE-2021-30613 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30613 Use after free in Base internals 4.1%
CVE-2021-30607 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30607 Use after free in Permissions 4.1%
CVE-2021-30606 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30606 Use after free in Blink 4.1%
CVE-2020-16924 HIGH 7.8 microsoft windows_10 <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.</p> <p>An attacker could explo 4.1%
CVE-2017-7064 MED 5.5 apple icloud An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit" component. It allows at 4.1%
CVE-2019-15992 HIGH 7.2 cisco adaptive_security_appliance A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root priv 4.1%
CVE-2014-0568 HIGH 10.0 adobe acrobat The NtSetInformationFile system call hook feature in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via an 4.1%
CVE-2024-21346 HIGH 7.8 microsoft windows_11_21h2 Win32k Elevation of Privilege Vulnerability 4.1%
CVE-2024-26211 HIGH 7.8 microsoft windows_10_1507 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 4.1%
CVE-2015-5210 MED 5.8 apache ambari Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the targetURI parameter. 4.1%
CVE-2013-3345 HIGH 10.0 adobe flash_player Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Linux, before 11.1.111.64 on Android 2.x and 3.x, and before 11.1.115.69 on Android 4.x allows attackers to execute arbitrary code or cause a d 4.1%
CVE-2017-5662 HIGH 7.3 apache batik In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application 4.1%
CVE-2020-3263 HIGH 7.5 cisco webex_meetings A vulnerability in Cisco Webex Meetings Desktop App could allow an unauthenticated, remote attacker to execute programs on an affected end-user system. The vulnerability is due to improper validation of input that is supplied to application URLs. The attacker 4.1%
CVE-2016-1421 HIGH 7.5 cisco ip_phone_8800_series_firmware A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability exist 4.1%
CVE-2021-37578 CRIT 9.8 apache juddi Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport for accessing UDDI services. RMI uses the default Java serialization mechanism to pass parameters in RMI invocati 4.1%
CVE-2020-11969 CRIT 9.8 apache tomee If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication. This affects Apache TomEE 8.0.0-M1 - 8.0.1, Apache TomEE 7.1 4.1%
CVE-2016-4965 HIGH 8.8 fortinet fortiwan Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup functionality to execute arbitrary commands with root privileges via the graph parameter to diagnosis_control.php. 4.1%
CVE-2012-2379 HIGH 10.0 apache cxf Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and atta 4.1%
CVE-2022-23742 HIGH 7.8 checkpoint endpoint_security Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpat 4.1%
CVE-2020-9656 HIGH 7.8 adobe premiere_rush Adobe Premiere Rush versions 1.5.12 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . 4.1%
CVE-2017-3046 MED 5.5 adobe acrobat Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser, related to contiguous code-stream parsing. 4.1%
CVE-2017-3045 MED 5.5 adobe acrobat Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser, related to the palette box. 4.1%
CVE-2017-3043 MED 5.5 adobe acrobat Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the collaboration functionality. 4.1%
CVE-2017-3791 CRIT 10.0 cisco cisco_prime_home A vulnerability in the web-based GUI of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication and execute actions with administrator privileges. The vulnerability is due to a processing error in the role-based access control 4.1%