56.864 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.864 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1714 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2021-1713 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2018-0321 | CRIT 9.8 | cisco prime_collaboration A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation (RMI) system. The vulnerability is due to an open port in the Network Interface and Configuration Engine | 3.1% | — |
| CVE-2018-6947 | HIGH 7.8 | microsoft windows_10 An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier allows a local low privileged user to gain elevation of privileges on Windows 7 (32 and 64bit), and denial of se | 3.1% | — |
| CVE-2012-6600 | HIGH 9.0 | paloaltonetworks pan-os The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 34502. | 3.1% | — |
| CVE-2006-5553 | HIGH 7.8 | cisco security_agent Cisco Security Agent (CSA) for Linux 4.5 before 4.5.1.657 and 5.0 before 5.0.0.193, as used by Unified CallManager (CUCM) and Unified Presence Server (CUPS), allows remote attackers to cause a denial of service (resource consumption) via a port scan with certa | 3.1% | — |
| CVE-2001-0851 | MED 5.0 | caldera openlinux Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie. | 3.1% | — |
| CVE-2021-39844 | LOW 3.3 | adobe acrobat Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the curre | 3.1% | — |
| CVE-2020-17058 | HIGH 7.5 | microsoft edge Microsoft Browser Memory Corruption Vulnerability | 3.1% | — |
| CVE-2018-1272 | HIGH 7.5 | oracle application_testing_suite Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote clie | 3.1% | — |
| CVE-2018-4374 | MED 6.1 | apple icloud A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8. | 3.1% | — |
| CVE-2010-1408 | MED 4.3 | apple safari WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to bypass intended restrictions on outbound connections to "non-default TCP ports" via a crafted port number, related to an "i | 3.1% | — |
| CVE-2020-3453 | MED 4.7 | cisco rv340_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series Routers could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands on the underlying operating system (OS) as a | 3.1% | — |
| CVE-2014-1730 | HIGH 7.8 | google chrome Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly store internationalization metadata, which allows remote attackers to bypass intended access restrictions by leveraging "type conf | 3.1% | — |
| CVE-2012-0386 | HIGH 7.8 | cisco ios The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S allows remote attackers to cause a denial of service (device reload) via a crafted username in a reverse SSH login att | 3.1% | — |
| CVE-2017-12250 | MED 5.3 | cisco wide_area_application_services A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an HTTP Application Optimization (AO) related process to restart, causing a partial denial of service (DoS) condi | 3.1% | — |
| CVE-2017-0233 | HIGH 8.3 | microsoft edge An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0241. | 3.1% | — |
| CVE-2016-6447 | CRIT 9.8 | cisco meeting_app A vulnerability in Cisco Meeting Server and Meeting App could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to 2.0.1, Acano Serv | 3.1% | — |
| CVE-2003-1581 | LOW 2.6 | apache http_server The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, r | 3.1% | — |
| CVE-2020-3140 | CRIT 9.8 | cisco prime_license_manager A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of user input o | 3.1% | — |
| CVE-2018-6186 | HIGH 8.8 | citrix netscaler Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges. | 3.1% | — |
| CVE-2021-37404 | CRIT 9.8 | apache hadoop There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or | 3.1% | — |
| CVE-2024-21322 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2018-8348 | MED 4.7 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 3.1% | — |
| CVE-2016-10764 | CRIT 9.8 | linux linux_kernel In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.c cqspi_setup_flash() function. There are CQSPI_MAX_CHIPSELECT elements in the ->f_pdata array so the ">" should be ">=" instead. | 3.1% | — |