56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.832 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2005-2242 | MED 5.0 | Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to cause a denial of service (memory consumption and restart) via crafted packets to (1) the CTI Manager (ctimgr.exe) or (2 | 3.9% | — |
| CVE-2014-0516 | HIGH 7.5 | adobe adobe_air Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow remote attackers to bypass the Same Origin Policy via unspecified vectors. | 3.9% | — |
| CVE-2008-3691 | HIGH 10.0 | vmware ace Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware A | 3.9% | — |
| CVE-2003-0007 | MED 5.0 | microsoft outlook Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificate | 3.9% | — |
| CVE-2018-8214 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. Th | 3.9% | — |
| CVE-2020-9680 | HIGH 8.8 | adobe prelude Adobe Prelude versions 9.0 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | 3.9% | — |
| CVE-2020-3779 | HIGH 8.8 | adobe photoshop_2020 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.9% | — |
| CVE-2020-3773 | HIGH 8.8 | adobe photoshop_2020 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.9% | — |
| CVE-2020-3732 | HIGH 8.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.9% | — |
| CVE-2020-3730 | HIGH 8.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.9% | — |
| CVE-2020-3729 | HIGH 8.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.9% | — |
| CVE-2020-3727 | HIGH 8.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.9% | — |
| CVE-2020-3722 | HIGH 8.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.9% | — |
| CVE-2020-9494 | HIGH 7.5 | apache traffic_server Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread. | 3.9% | — |
| CVE-2008-2054 | HIGH 9.3 | cisco ciscoworks_common_services Unspecified vulnerability in Cisco CiscoWorks Common Services 3.0.3 through 3.1.1 allows remote attackers to execute arbitrary code on a client machine via unknown vectors. | 3.9% | — |
| CVE-2018-0274 | HIGH 8.8 | cisco network_services_orchestrator A vulnerability in the CLI parser of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insufficient input validation. An | 3.9% | — |
| CVE-2016-1006 | HIGH 8.1 | adobe air_desktop_runtime Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to bypass the ASLR protection mechanism via JIT data. | 3.9% | — |
| CVE-2005-3176 | HIGH 7.5 | microsoft windows_2000 Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection. | 3.9% | — |
| CVE-2005-2872 | MED 5.0 | linux linux_kernel The ipt_recent kernel module (ipt_recent.c) in Linux kernel before 2.6.12, when running on 64-bit processors such as AMD64, allows remote attackers to cause a denial of service (kernel panic) via certain attacks such as SSH brute force, which leads to memset c | 3.9% | — |
| CVE-2019-1642 | MED 6.1 | cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the | 3.9% | — |
| CVE-2025-50177 | HIGH 8.1 | microsoft windows_10_1507 Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | 3.9% | — |
| CVE-2020-0645 | HIGH 7.5 | microsoft windows_10 A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request headers, aka 'Microsoft IIS Server Tampering Vulnerability'. | 3.9% | — |
| CVE-2021-24019 | HIGH 8.1 | fortinet forticlient_endpoint_management_server An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that ses | 3.9% | — |
| CVE-2021-26423 | HIGH 7.5 | microsoft .net .NET Core and Visual Studio Denial of Service Vulnerability | 3.9% | — |
| CVE-2020-0856 | MED 6.5 | microsoft windows_server_2008 <p>An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. An authenticated attacker who successfully exploited this vulnerability would be able to read sensitive information about the target s | 3.9% | — |