56.864 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.864 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-36970 | HIGH 8.8 | microsoft windows_10 Windows Print Spooler Spoofing Vulnerability | 3.1% | — |
| CVE-2013-4390 | MED 5.8 | apache sling Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Sling allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in th | 3.1% | — |
| CVE-2021-31812 | MED 5.5 | apache pdfbox In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. | 3.1% | — |
| CVE-2021-26868 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 3.1% | — |
| CVE-2019-1193 | MED 6.4 | microsoft edge A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who | 3.1% | — |
| CVE-2018-3251 | MED 6.5 | canonical ubuntu_linux Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network a | 3.1% | — |
| CVE-2024-43485 | HIGH 7.5 | microsoft .net .NET and Visual Studio Denial of Service Vulnerability | 3.1% | — |
| CVE-2022-21911 | HIGH 7.5 | microsoft .net_framework .NET Framework Denial of Service Vulnerability | 3.1% | — |
| CVE-2021-41561 | HIGH 7.5 | apache parquet_java Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions. | 3.1% | — |
| CVE-2015-2922 | LOW 3.3 | debian debian_linux The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Route | 3.1% | — |
| CVE-2015-1680 | LOW 2.1 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protec | 3.1% | — |
| CVE-2015-1679 | LOW 2.1 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protec | 3.1% | — |
| CVE-2015-1678 | LOW 2.1 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protec | 3.1% | — |
| CVE-2015-1677 | LOW 2.1 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protec | 3.1% | — |
| CVE-2015-1676 | LOW 2.1 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protec | 3.1% | — |
| CVE-2015-0691 | HIGH 9.3 | cisco secure_desktop A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a crafted web site, aka Bug ID CSCup83001. | 3.1% | — |
| CVE-2020-9487 | HIGH 7.5 | apache nifi In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to use the token to access the content. An unauthenticated user co | 3.0% | — |
| CVE-2018-19451 | HIGH 7.8 | foxitsoftware foxit_pdf_sdk_activex A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when using the Open File action on a Field. An attacker can leverage this to gain remote code execution. | 3.0% | — |
| CVE-2017-17671 | CRIT 9.8 | vbulletin vbulletin vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can include directory traversal sequences to specify an arbitrary pathname, and because ../ traversal is blocked b | 3.0% | — |
| CVE-2023-24860 | HIGH 7.5 | microsoft malware_protection_engine Microsoft Defender Denial of Service Vulnerability | 3.0% | — |
| CVE-2019-6773 | MED 5.5 | foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious | 3.0% | — |
| CVE-2019-0001 | HIGH 7.5 | fedoraproject fedora Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge subscriber management daemon (bbe-smgd), and lead to high CPU usage and a crash of the bbe-smgd service. Repeate | 3.0% | — |
| CVE-2016-9219 | HIGH 7.5 | cisco wireless_lan_controller_firmware A vulnerability with IPv6 UDP ingress packet processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an unexpected reload of the device. The vulnerability is due to incomplete IPv6 UDP header validati | 3.0% | — |
| CVE-2021-31176 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 3.0% | — |
| CVE-2022-21996 | HIGH 7.8 | microsoft windows_11 Win32k Elevation of Privilege Vulnerability | 3.0% | — |