IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.855 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2012-3373 MED 4.3 apache wicket Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app. 3.3%
CVE-2023-50291 HIGH 7.5 apache solr Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.0. One of the two endpoints that publishes the Solr process' Java system properties, /admin/info/properties, wa 3.3%
CVE-2019-1080 HIGH 7.5 microsoft internet_explorer A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. 3.3%
CVE-2019-1038 HIGH 7.5 microsoft edge A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who 3.3%
CVE-2019-13135 HIGH 8.8 canonical ubuntu_linux ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c. 3.3%
CVE-2025-49125 HIGH 7.5 apache tomcat Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That pat 3.3%
CVE-2017-9479 CRIT 9.8 cisco dpc3939_firmware The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to execute arbitrary commands as root by leveraging local network access and connecting to the syseventd server, as demonstrated 3.3%
CVE-2008-3496 HIGH 10.0 linux linux_kernel Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors. 3.3%
CVE-2004-1434 MED 5.0 cisco optical_networking_systems_software Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.1(0) to 4.1(2), 4.5(x), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via malformed SNMP packets. 3.3%
CVE-2019-8244 MED 4.3 adobe media_encoder Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. 3.3%
CVE-2019-8243 MED 4.3 adobe media_encoder Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. 3.3%
CVE-2019-8242 MED 4.3 adobe media_encoder Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. 3.3%
CVE-2019-8241 MED 4.3 adobe media_encoder Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. 3.3%
CVE-2016-7220 LOW 3.3 microsoft windows_10 Virtual Secure Mode in Microsoft Windows 10 allows local users to obtain sensitive information via a crafted application, aka "Virtual Secure Mode Information Disclosure Vulnerability." 3.3%
CVE-2005-0209 HIGH 7.8 linux linux_kernel Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments. 3.3%
CVE-2006-6333 HIGH 7.8 linux linux_kernel The tr_rx function in ibmtr.c for Linux kernel 2.6.19 assigns the wrong flag to the ip_summed field, which allows remote attackers to cause a denial of service (memory corruption) via crafted packets that cause the kernel to interpret another field as an offse 3.3%
CVE-2025-27740 HIGH 8.8 microsoft windows_server_2008 Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network. 3.3%
CVE-2022-34724 HIGH 7.5 microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability 3.3%
CVE-2021-24112 HIGH 8.1 microsoft .net .NET Core Remote Code Execution Vulnerability 3.3%
CVE-2022-26924 HIGH 7.5 microsoft yet_another_reverse_proxy YARP Denial of Service Vulnerability 3.3%
CVE-2020-1061 HIGH 7.5 microsoft windows_10 A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attac 3.3%
CVE-2014-3380 MED 5.0 cisco unified_communications_domain_manager_platform Cisco Unified Communications Domain Manager Platform Software 4.4(.3) and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending crafted TCP packets quickly, aka Bug ID CSCuo42063. 3.3%
CVE-2004-1056 MED 6.4 linux linux_kernel Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, which could allow remote attackers or local users to cause a denial of service (X Server crash) and possibly modify the video output. 3.3%
CVE-2021-36960 HIGH 7.5 microsoft windows_10 Windows SMB Information Disclosure Vulnerability 3.3%
CVE-2020-1112 HIGH 8.5 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content. An attacker who successfully exploited this vulnerability could upload restricted file types to an II 3.3%