56.864 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.864 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-24429 | HIGH 7.7 | adobe acrobat Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a signature verification bypass that could result in local privilege escalation. Exploitation of this issue require | 3.0% | — |
| CVE-2019-10639 | HIGH 7.5 | linux linux_kernel The Linux kernel 4.x (starting from 4.1) and 5.x before 5.0.8 allows Information Exposure (partial kernel address disclosure), leading to a KASLR bypass. Specifically, it is possible to extract the KASLR kernel image offset using the IP ID values the kernel pr | 3.0% | — |
| CVE-2018-0349 | CRIT 9.8 | cisco vbond_orchestrator A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the request admin-tech co | 3.0% | — |
| CVE-2016-5023 | HIGH 7.5 | f5 big-ip_access_policy_manager Virtual servers in F5 BIG-IP systems 11.2.1 HF11 through HF15, 11.4.1 HF4 through HF10, 11.5.3 through 11.5.4, 11.6.0 HF5 through HF7, and 12.0.0, when configured with a TCP profile, allow remote attackers to cause a denial of service (Traffic Management Micro | 3.0% | — |
| CVE-2022-26831 | HIGH 7.5 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | 3.0% | — |
| CVE-2019-1580 | CRIT 9.8 | paloaltonetworks pan-os Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow a remote, unauthenticated user to craft a message to Secure Shell Daemon (SSHD) and corrupt arbitrary memory. | 3.0% | — |
| CVE-2016-1469 | HIGH 7.5 | cisco spa300_firmware The HTTP framework on Cisco SPA300, SPA500, and SPA51x devices allows remote attackers to cause a denial of service (device outage) via a series of malformed HTTP requests, aka Bug ID CSCut67385. | 3.0% | — |
| CVE-2016-1344 | MED 5.9 | cisco ios_xe The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417. | 3.0% | — |
| CVE-2021-26859 | HIGH 7.7 | microsoft power_bi_report_server Microsoft Power BI Information Disclosure Vulnerability | 3.0% | — |
| CVE-2017-8685 | MED 5.5 | microsoft windows_7 Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8684 and | 3.0% | — |
| CVE-2020-3297 | CRIT 9.8 | cisco sf200-24_firmware A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to defeat authentication protections and gain unauthorized access to the management interface. | 3.0% | — |
| CVE-2019-0958 | HIGH 8.8 | microsoft sharepoint_foundation An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique | 3.0% | — |
| CVE-2018-8604 | MED 4.3 | microsoft exchange_server A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server. | 3.0% | — |
| CVE-2020-3490 | MED 4.9 | cisco vision_dynamic_signage_director A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an authenticated, remote attacker with administrative privileges to conduct directory traversal attacks and obtain read access to sensitive files on an a | 3.0% | — |
| CVE-2019-0941 | MED 4.4 | microsoft windows_10 A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests. An attacker who successfully exploited this vulnerability could perform a temporary denial of service against pages configured to use re | 3.0% | — |
| CVE-2008-3697 | MED 5.0 | vmware server An unspecified ISAPI extension in VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (IIS crash) via a malformed request. | 3.0% | — |
| CVE-2023-38426 | CRIT 9.1 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length. | 3.0% | — |
| CVE-2010-2057 | MED 5.0 | apache myfaces shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modification | 3.0% | — |
| CVE-2018-3997 | HIGH 8.8 | foxitsoftware phantompdf An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.2.0.9297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code exe | 3.0% | — |
| CVE-2025-59501 | MED 4.8 | microsoft configuration_manager_2403 Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network. | 3.0% | — |
| CVE-2021-27066 | MED 4.3 | microsoft windows_admin_center Windows Admin Center Security Feature Bypass Vulnerability | 3.0% | — |
| CVE-2007-4747 | HIGH 10.0 | cisco video_surveillance_ip_gateway_encoder_decoder The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier | 3.0% | — |
| CVE-2021-21133 | MED 6.5 | google chrome Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attacker who convinced a user to download files to bypass navigation restrictions via a crafted HTML page. | 3.0% | — |
| CVE-2019-1345 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1334. | 3.0% | — |
| CVE-2019-8096 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful ex | 3.0% | — |