56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.855 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38150 | HIGH 7.8 | microsoft windows_10_21h2 Windows DWM Core Library Elevation of Privilege Vulnerability | 3.7% | — |
| CVE-2017-5123 | HIGH 8.8 | linux linux_kernel Insufficient data validation in waitid allowed an user to escape sandboxes on Linux. | 3.7% | — |
| CVE-2022-26815 | HIGH 7.2 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 3.7% | — |
| CVE-2022-26813 | HIGH 7.2 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 3.7% | — |
| CVE-2022-26812 | HIGH 7.2 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 3.7% | — |
| CVE-2022-24536 | HIGH 7.2 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 3.7% | — |
| CVE-2019-1192 | MED 4.3 | microsoft edge A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwise be | 3.7% | — |
| CVE-2017-8492 | MED 5.0 | microsoft windows_10 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a spe | 3.7% | — |
| CVE-2017-8488 | MED 5.0 | microsoft windows_7 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a spe | 3.7% | — |
| CVE-2017-8484 | MED 5.0 | microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when | 3.7% | — |
| CVE-2017-8482 | MED 5.0 | microsoft windows_10 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a spe | 3.7% | — |
| CVE-2017-8478 | MED 5.0 | microsoft windows_10 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a spe | 3.7% | — |
| CVE-2017-8462 | MED 5.0 | microsoft windows_10 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a spe | 3.7% | — |
| CVE-2008-1152 | HIGH 7.8 | cisco cisco_ios The data-link switching (DLSw) component in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device restart or memory consumption) via crafted (1) UDP port 2067 or (2) IP protocol 91 packets. | 3.7% | — |
| CVE-2005-2457 | MED 5.0 | linux linux_kernel The driver for compressed ISO file systems (zisofs) in the Linux kernel before 2.6.12.5 allows local users and remote attackers to cause a denial of service (kernel crash) via a crafted compressed ISO file system. | 3.7% | — |
| CVE-2026-26030 | CRIT 9.9 | microsoft semantic_kernel Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `python-1.39.4`. Users sho | 3.7% | — |
| CVE-2014-0499 | HIGH 7.8 | adobe adobe_air Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 | 3.7% | — |
| CVE-1999-0289 | MED 5.0 | apache http_server The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL. | 3.7% | — |
| CVE-2019-0555 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows Server | 3.7% | — |
| CVE-2023-36778 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 3.7% | — |
| CVE-2003-1580 | MED 4.3 | apache http_server The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS r | 3.7% | — |
| CVE-2022-29110 | HIGH 7.8 | microsoft excel Microsoft Excel Remote Code Execution Vulnerability | 3.7% | — |
| CVE-2013-2684 | MED 6.1 | cisco linksys_e4200_firmware Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 3.7% | — |
| CVE-2021-40525 | CRIT 9.1 | apache james Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. D | 3.7% | — |
| CVE-2019-8206 | CRIT 9.8 | adobe acrobat_dc Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to | 3.7% | — |