56.807 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.807 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-30618 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30618 Inappropriate implementation in DevTools | 4.1% | — |
| CVE-2021-30613 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30613 Use after free in Base internals | 4.1% | — |
| CVE-2021-30607 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30607 Use after free in Permissions | 4.1% | — |
| CVE-2021-30606 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30606 Use after free in Blink | 4.1% | — |
| CVE-2020-16924 | HIGH 7.8 | microsoft windows_10 <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.</p> <p>An attacker could explo | 4.1% | — |
| CVE-2017-7064 | MED 5.5 | apple icloud An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit" component. It allows at | 4.1% | — |
| CVE-2019-15992 | HIGH 7.2 | cisco adaptive_security_appliance A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root priv | 4.1% | — |
| CVE-2014-0568 | HIGH 10.0 | adobe acrobat The NtSetInformationFile system call hook feature in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via an | 4.1% | — |
| CVE-2024-21346 | HIGH 7.8 | microsoft windows_11_21h2 Win32k Elevation of Privilege Vulnerability | 4.1% | — |
| CVE-2024-26211 | HIGH 7.8 | microsoft windows_10_1507 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 4.1% | — |
| CVE-2015-5210 | MED 5.8 | apache ambari Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the targetURI parameter. | 4.1% | — |
| CVE-2013-3345 | HIGH 10.0 | adobe flash_player Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Linux, before 11.1.111.64 on Android 2.x and 3.x, and before 11.1.115.69 on Android 4.x allows attackers to execute arbitrary code or cause a d | 4.1% | — |
| CVE-2017-5662 | HIGH 7.3 | apache batik In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application | 4.1% | — |
| CVE-2020-3263 | HIGH 7.5 | cisco webex_meetings A vulnerability in Cisco Webex Meetings Desktop App could allow an unauthenticated, remote attacker to execute programs on an affected end-user system. The vulnerability is due to improper validation of input that is supplied to application URLs. The attacker | 4.1% | — |
| CVE-2016-1421 | HIGH 7.5 | cisco ip_phone_8800_series_firmware A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability exist | 4.1% | — |
| CVE-2021-37578 | CRIT 9.8 | apache juddi Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport for accessing UDDI services. RMI uses the default Java serialization mechanism to pass parameters in RMI invocati | 4.1% | — |
| CVE-2020-11969 | CRIT 9.8 | apache tomee If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication. This affects Apache TomEE 8.0.0-M1 - 8.0.1, Apache TomEE 7.1 | 4.1% | — |
| CVE-2016-4965 | HIGH 8.8 | fortinet fortiwan Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup functionality to execute arbitrary commands with root privileges via the graph parameter to diagnosis_control.php. | 4.1% | — |
| CVE-2012-2379 | HIGH 10.0 | apache cxf Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and atta | 4.1% | — |
| CVE-2022-23742 | HIGH 7.8 | checkpoint endpoint_security Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpat | 4.1% | — |
| CVE-2020-9656 | HIGH 7.8 | adobe premiere_rush Adobe Premiere Rush versions 1.5.12 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | 4.1% | — |
| CVE-2017-3046 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser, related to contiguous code-stream parsing. | 4.1% | — |
| CVE-2017-3045 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser, related to the palette box. | 4.1% | — |
| CVE-2017-3043 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the collaboration functionality. | 4.1% | — |
| CVE-2017-3791 | CRIT 10.0 | cisco cisco_prime_home A vulnerability in the web-based GUI of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication and execute actions with administrator privileges. The vulnerability is due to a processing error in the role-based access control | 4.1% | — |