56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.832 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-45067 | MED 5.5 | adobe acrobat Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Access of Memory Location After End of Buffer vulnerability that could lead to disclosure of sensitive memory. An attacker could | 3.9% | — |
| CVE-2019-7102 | CRIT 9.8 | adobe shockwave_player Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.9% | — |
| CVE-2019-7101 | CRIT 9.8 | adobe shockwave_player Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.9% | — |
| CVE-2023-32247 | HIGH 7.5 | linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_SESSION_SETUP commands. The issue results from the lack of control of resource consumption. An attacker can leverage thi | 3.9% | — |
| CVE-2022-41674 | HIGH 8.1 | debian debian_linux An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c. | 3.9% | — |
| CVE-2021-43224 | MED 5.5 | microsoft windows_10 Windows Common Log File System Driver Information Disclosure Vulnerability | 3.9% | — |
| CVE-2009-1298 | HIGH 7.8 | linux linux_kernel The ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel 2.6.32-rc8, and 2.6.29 and later versions before 2.6.32, calls IP_INC_STATS_BH with an incorrect argument, which allows remote attackers to cause a denial of service (NULL pointer derefer | 3.9% | — |
| CVE-2007-3642 | HIGH 7.8 | linux linux_kernel The decode_choice function in net/netfilter/nf_conntrack_h323_asn1.c in the Linux kernel before 2.6.20.15, 2.6.21.x before 2.6.21.6, and before 2.6.22 allows remote attackers to cause a denial of service (crash) via an encoded, out-of-range index value for a c | 3.9% | — |
| CVE-2007-0772 | HIGH 7.8 | linux linux_kernel The Linux kernel 2.6.13 and other versions before 2.6.20.1 allows remote attackers to cause a denial of service (oops) via a crafted NFSACL 2 ACCESS request that triggers a free of an incorrect pointer. | 3.9% | — |
| CVE-2020-16957 | HIGH 7.8 | microsoft 365_apps <p>A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.</p> <p>An atta | 3.9% | — |
| CVE-2020-1512 | HIGH 7.8 | microsoft windows_10 An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. An attack | 3.9% | — |
| CVE-2019-6767 | HIGH 7.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. Th | 3.9% | — |
| CVE-2018-8134 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, W | 3.9% | — |
| CVE-2022-29063 | CRIT 9.8 | apache ofbiz The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or | 3.9% | — |
| CVE-2017-3161 | MED 6.1 | apache hadoop The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter. | 3.9% | — |
| CVE-2001-0090 | MED 5.1 | microsoft internet_explorer The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the "Browser Print Template" vulnerability. | 3.9% | — |
| CVE-2021-21095 | HIGH 7.8 | adobe bridge Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Out-of-bounds write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the conte | 3.9% | — |
| CVE-2021-21094 | HIGH 7.8 | adobe bridge Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Out-of-bounds write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in | 3.9% | — |
| CVE-2022-24507 | HIGH 7.8 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 3.9% | — |
| CVE-2002-0340 | HIGH 7.5 | microsoft windows_media_player Windows Media Player (WMP) 8.00.00.4477, and possibly other versions, automatically detects and executes .wmf and other content, even when the file's extension or content type does not specify .wmf, which could make it easier for attackers to conduct unauthori | 3.9% | — |
| CVE-2021-40439 | MED 6.5 | apache openoffice Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consist of a set of XML files. All versions of | 3.9% | — |
| CVE-2023-32783 | HIGH 7.5 | zohocorp manageengine_adaudit_plus The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an exp | 3.9% | — |
| CVE-2020-16918 | HIGH 7.8 | microsoft 365_apps <p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An attacker who successfully exploited the vulnerability would gain execution on a victim system.</p> <p>The security update addresses the vulner | 3.9% | — |
| CVE-2020-9674 | HIGH 7.8 | adobe bridge Adobe Bridge versions 10.0.3 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 3.9% | — |
| CVE-2006-0454 | MED 5.0 | linux linux_kernel Linux kernel before 2.6.15.3 down to 2.6.12, while constructing an ICMP response in icmp_send, does not properly handle when the ip_options_echo function in icmp.c fails, which allows remote attackers to cause a denial of service (crash) via vectors such as (1 | 3.9% | — |