56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.855 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-13097 | MED 5.5 | linux linux_kernel An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.17.3. There is an out-of-bounds read or a divide-by-zero error for an incorrect user_block_count in a corrupted f2fs image, leading to a denial of service (BUG). | 3.5% | — |
| CVE-2012-4078 | HIGH 8.5 | cisco unified_computing_system The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote authenticated users to bypass an unspecified authentication step via SSH port forwarding, aka Bug ID CSCtg17656 | 3.5% | — |
| CVE-2022-31813 | CRIT 9.8 | apache http_server Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application. | 3.5% | — |
| CVE-2021-27577 | HIGH 7.5 | apache traffic_server Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. | 3.5% | — |
| CVE-2018-1000004 | MED 5.9 | linux linux_kernel In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race condition vulnerability exists in the sound system, this can lead to a deadlock and denial of service condition. | 3.5% | — |
| CVE-2014-2401 | MED 5.0 | ibm forms_viewer Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality via unknown vectors related to 2D. | 3.5% | — |
| CVE-2024-22252 | CRIT 9.3 | vmware esxi VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runn | 3.5% | — |
| CVE-2018-8030 | HIGH 7.5 | apache qpid_broker-j A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB by default). The broker crashes due to t | 3.5% | — |
| CVE-2017-0256 | MED 5.3 | microsoft asp.net_model_view_controller A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | 3.5% | — |
| CVE-2005-3180 | MED 5.0 | linux linux_kernel The Orinoco driver (orinoco.c) in Linux kernel 2.6.13 and earlier does not properly clear memory from a previously used packet whose length is increased, which allows remote attackers to obtain sensitive information. | 3.5% | — |
| CVE-2009-1792 | HIGH 9.3 | stonetrip s3dplayer_standalone The system.openURL function in StoneTrip Ston3D StandalonePlayer (aka S3DPlayer StandAlone) 1.6.2.4 and 1.7.0.1 and WebPlayer (aka S3DPlayer Web) 1.6.0.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the first argument (the | 3.5% | — |
| CVE-2021-26433 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 3.5% | — |
| CVE-2021-27058 | HIGH 7.8 | microsoft 365_apps Microsoft Office ClickToRun Remote Code Execution Vulnerability | 3.5% | — |
| CVE-2019-5589 | HIGH 7.8 | fortinet forticlient An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control over the directory in which FortiClientOnlineInstaller.exe resides to execute arbitrary code on the sy | 3.5% | — |
| CVE-2012-0803 | CRIT 9.8 | apache cxf The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as part of a SOAP request. | 3.5% | — |
| CVE-2015-2114 | MED 6.8 | hp support_solution_framework HP Support Solution Framework before 11.51.0049 allows remote attackers to download an arbitrary program onto a client machine and execute this program via unspecified vectors. | 3.5% | — |
| CVE-2008-0600 | HIGH 7.2 | linux linux_kernel The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different vulnerability | 3.5% | — |
| CVE-2021-28553 | HIGH 8.8 | adobe acrobat Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary | 3.5% | — |
| CVE-2019-19447 | HIGH 7.8 | linux linux_kernel In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c. | 3.5% | — |
| CVE-2023-21552 | HIGH 7.8 | microsoft windows_10_1607 Windows GDI Elevation of Privilege Vulnerability | 3.5% | — |
| CVE-2020-24588 | LOW 3.5 | arista c-100_firmware The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU fr | 3.5% | — |
| CVE-2019-0654 | MED 4.3 | microsoft edge A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'. | 3.5% | — |
| CVE-2009-3902 | MED 5.0 | cherokee cherokee_httpd Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (slash backslash dot dot) in the URL. | 3.5% | — |
| CVE-2000-1027 | MED 5.0 | cisco pix_firewall_software Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive mode is established. | 3.5% | — |
| CVE-2022-28242 | HIGH 7.8 | adobe acrobat Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of thi | 3.5% | — |