56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.855 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1136 | HIGH 8.1 | microsoft exchange_server An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. | 3.3% | — |
| CVE-2014-4014 | MED 6.2 | linux linux_kernel The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setti | 3.3% | — |
| CVE-2018-0264 | CRIT 9.6 | cisco webex_business_suite_31 A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on the system of a targeted user. An attacker could exploit this vulnerability by se | 3.3% | — |
| CVE-2024-38346 | CRIT 9.8 | apache cloudstack The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and CloudStack management server hosts. Some of these commands were found to have command injection vulnerabilities | 3.3% | — |
| CVE-2020-29016 | CRIT 9.8 | fortinet fortiweb A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to overwrite the content of the stack and potentially execute arbitrary code by sending a crafted request with a | 3.3% | — |
| CVE-2017-8575 | MED 5.5 | microsoft windows_10 The kernel in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application, aka "Microsoft Graphics Component Information Disclosure Vulnerability." | 3.3% | — |
| CVE-2022-30158 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 3.3% | — |
| CVE-2022-20755 | CRIT 9.0 | cisco telepresence_video_communication_server Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write file | 3.3% | — |
| CVE-2022-20754 | CRIT 9.0 | cisco telepresence_video_communication_server Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write file | 3.3% | — |
| CVE-2021-41338 | MED 5.5 | microsoft windows_10 Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability | 3.3% | — |
| CVE-2008-3805 | HIGH 8.5 | cisco ios Cisco IOS 12.0 through 12.4 on Cisco 10000, uBR10012 and uBR7200 series devices handles external UDP packets that are sent to 127.0.0.0/8 addresses intended for IPC communication within the device, which allows remote attackers to cause a denial of service (de | 3.3% | — |
| CVE-2021-33580 | HIGH 7.5 | apache roller User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programmatically. | 3.3% | — |
| CVE-2019-6471 | MED 5.9 | f5 big-ip_access_policy_manager A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the BIND 9.13 | 3.3% | — |
| CVE-2007-3304 | MED 4.7 | apache http_server Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master proc | 3.3% | — |
| CVE-2019-19814 | HIGH 7.8 | linux linux_kernel In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this. | 3.3% | — |
| CVE-2002-1024 | HIGH 7.1 | cisco catos Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144). | 3.3% | — |
| CVE-2020-17133 | MED 6.5 | microsoft dynamics_nav Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability | 3.3% | — |
| CVE-2017-0180 | HIGH 7.6 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is | 3.3% | — |
| CVE-2015-1721 | HIGH 7.2 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to gain privil | 3.3% | — |
| CVE-2024-49062 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Information Disclosure Vulnerability | 3.3% | — |
| CVE-2008-4934 | HIGH 7.8 | canonical ubuntu_linux The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) v | 3.3% | — |
| CVE-2019-19816 | HIGH 7.8 | canonical ubuntu_linux In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a value of 1 for the number of data stripes is mishandled. | 3.3% | — |
| CVE-2019-1871 | HIGH 7.2 | cisco integrated_management_controller_supervisor A vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and implement arbitrary commands with root privileges on an | 3.3% | — |
| CVE-2019-7079 | HIGH 8.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code executi | 3.3% | — |
| CVE-2008-4390 | HIGH 7.5 | cisco linksys_wvc54gc_firmware The Cisco Linksys WVC54GC wireless video camera before firmware 1.25 sends cleartext configuration data in response to a Setup Wizard remote-management command, which allows remote attackers to obtain sensitive information such as passwords by sniffing the net | 3.3% | — |