56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.855 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-4926 | MED 5.5 | adobe digital_editions Adobe Digital Editions versions 4.5.7 and below have an exploitable Stack Overflow vulnerability. Successful exploitation could lead to information disclosure. | 3.6% | — |
| CVE-2010-4805 | HIGH 7.5 | linux linux_kernel The socket implementation in net/core/sock.c in the Linux kernel before 2.6.35 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service by sending a large amount of network traffic, related to the sk_ad | 3.6% | — |
| CVE-2021-45485 | HIGH 7.5 | linux linux_kernel In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 so | 3.6% | — |
| CVE-2021-23338 | MED 6.6 | microsoft qlib This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function. | 3.6% | — |
| CVE-2021-1711 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 3.6% | — |
| CVE-2021-28576 | MED 4.3 | adobe animate Adobe Animate version 21.0.5 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current u | 3.6% | — |
| CVE-2019-0867 | MED 6.1 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique f | 3.6% | — |
| CVE-2018-1330 | HIGH 7.5 | apache mesos When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A ma | 3.6% | — |
| CVE-2019-8250 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a type confusion vulnerability. Successful exploit | 3.6% | — |
| CVE-2019-8249 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a type confusion vulnerability. Successful exploit | 3.6% | — |
| CVE-2021-1707 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 3.6% | — |
| CVE-2021-1701 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 3.6% | — |
| CVE-2021-1700 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 3.6% | — |
| CVE-2021-1667 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 3.6% | — |
| CVE-2007-6037 | MED 4.3 | citrix netscaler Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter and other unspecified parameters. | 3.6% | — |
| CVE-2024-21312 | HIGH 7.5 | microsoft .net_framework .NET Framework Denial of Service Vulnerability | 3.6% | — |
| CVE-2023-5528 | HIGH 7.2 | fedoraproject fedora A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugi | 3.6% | — |
| CVE-2019-1971 | CRIT 9.8 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulnerability is due to ins | 3.6% | — |
| CVE-2020-9567 | HIGH 7.8 | adobe bridge Adobe Bridge versions 10.0.1 and earlier version have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution . | 3.6% | — |
| CVE-2008-3538 | HIGH 9.0 | hp enterprise_discovery Unspecified vulnerability in HP Enterprise Discovery 2.0 through 2.52 on Windows allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the initial description of this CVE was inadvertently associated with libxml2, but it shoul | 3.6% | — |
| CVE-2022-47942 | HIGH 8.8 | linux linux_kernel An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command. | 3.6% | — |
| CVE-2019-1258 | HIGH 8.8 | microsoft active_directory_authentication_library An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in the way the library caches tokens. This vulnerability allows an authenticated attacker to perform actions in context of another user. The auth | 3.6% | — |
| CVE-2019-12615 | HIGH 7.5 | linux linux_kernel An issue was discovered in get_vdev_port_node_info in arch/sparc/kernel/mdesc.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup_const of node_info->vdev_port.name, which might allow an attacker to cause a denial of service (NULL pointer derefe | 3.6% | — |
| CVE-2016-6406 | CRIT 9.8 | cisco email_security_appliance_firmware Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client before 1.0.2-065 is installed, allows remote attackers to obtain root access v | 3.6% | — |
| CVE-2024-43560 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability | 3.6% | — |