IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.855 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-1136 HIGH 8.1 microsoft exchange_server An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. 3.3%
CVE-2014-4014 MED 6.2 linux linux_kernel The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setti 3.3%
CVE-2018-0264 CRIT 9.6 cisco webex_business_suite_31 A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on the system of a targeted user. An attacker could exploit this vulnerability by se 3.3%
CVE-2024-38346 CRIT 9.8 apache cloudstack The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and CloudStack management server hosts. Some of these commands were found to have command injection vulnerabilities 3.3%
CVE-2020-29016 CRIT 9.8 fortinet fortiweb A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to overwrite the content of the stack and potentially execute arbitrary code by sending a crafted request with a 3.3%
CVE-2017-8575 MED 5.5 microsoft windows_10 The kernel in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application, aka "Microsoft Graphics Component Information Disclosure Vulnerability." 3.3%
CVE-2022-30158 HIGH 8.8 microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability 3.3%
CVE-2022-20755 CRIT 9.0 cisco telepresence_video_communication_server Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write file 3.3%
CVE-2022-20754 CRIT 9.0 cisco telepresence_video_communication_server Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write file 3.3%
CVE-2021-41338 MED 5.5 microsoft windows_10 Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability 3.3%
CVE-2008-3805 HIGH 8.5 cisco ios Cisco IOS 12.0 through 12.4 on Cisco 10000, uBR10012 and uBR7200 series devices handles external UDP packets that are sent to 127.0.0.0/8 addresses intended for IPC communication within the device, which allows remote attackers to cause a denial of service (de 3.3%
CVE-2021-33580 HIGH 7.5 apache roller User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programmatically. 3.3%
CVE-2019-6471 MED 5.9 f5 big-ip_access_policy_manager A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the BIND 9.13 3.3%
CVE-2007-3304 MED 4.7 apache http_server Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master proc 3.3%
CVE-2019-19814 HIGH 7.8 linux linux_kernel In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this. 3.3%
CVE-2002-1024 HIGH 7.1 cisco catos Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144). 3.3%
CVE-2020-17133 MED 6.5 microsoft dynamics_nav Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability 3.3%
CVE-2017-0180 HIGH 7.6 microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is 3.3%
CVE-2015-1721 HIGH 7.2 microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to gain privil 3.3%
CVE-2024-49062 MED 6.5 microsoft sharepoint_server Microsoft SharePoint Information Disclosure Vulnerability 3.3%
CVE-2008-4934 HIGH 7.8 canonical ubuntu_linux The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) v 3.3%
CVE-2019-19816 HIGH 7.8 canonical ubuntu_linux In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a value of 1 for the number of data stripes is mishandled. 3.3%
CVE-2019-1871 HIGH 7.2 cisco integrated_management_controller_supervisor A vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and implement arbitrary commands with root privileges on an 3.3%
CVE-2019-7079 HIGH 8.8 adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code executi 3.3%
CVE-2008-4390 HIGH 7.5 cisco linksys_wvc54gc_firmware The Cisco Linksys WVC54GC wireless video camera before firmware 1.25 sends cleartext configuration data in response to a Setup Wizard remote-management command, which allows remote attackers to obtain sensitive information such as passwords by sniffing the net 3.3%