56.932 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.932 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2008-5545 | HIGH 9.3 | trend_micro trend_micro_antivirus Trend Micro VSAPI 8.700.0.1004 in Trend Micro AntiVirus, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to | 3.0% | — |
| CVE-2008-5543 | HIGH 9.3 | symantec antivirus Symantec AntiVirus (SAV) 10, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a | 3.0% | — |
| CVE-2008-5535 | HIGH 9.3 | norman norman_antivirus_\&_antispyware Norman Antivirus 5.80.02, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .t | 3.0% | — |
| CVE-2008-5533 | HIGH 9.3 | k7computing antivirus K7AntiVirus 7.10.541 and possibly 7.10.454, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no e | 3.0% | — |
| CVE-2008-5531 | HIGH 9.3 | fortinet fortiguard_antivirus Fortinet Antivirus 3.113.0.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) | 3.0% | — |
| CVE-2008-5526 | HIGH 9.3 | drweb anti-virus DrWeb Anti-virus 4.44.0.09170, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) | 3.0% | — |
| CVE-2018-8026 | MED 5.5 | apache solr This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config file). In addition, Xinclude functional | 2.9% | — |
| CVE-2016-5336 | CRIT 9.8 | vmware vrealize_automation VMware vRealize Automation 7.0.x before 7.1 allows remote attackers to execute arbitrary code via unspecified vectors. | 2.9% | — |
| CVE-2014-3351 | MED 5.0 | cisco cloud_portal Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, aka Bug IDs CSCuh87398 and CSCuh87380 | 2.9% | — |
| CVE-2019-19079 | HIGH 7.5 | canonical ubuntu_linux A memory leak in the qrtr_tun_write_iter() function in net/qrtr/tun.c in the Linux kernel before 5.3 allows attackers to cause a denial of service (memory consumption), aka CID-a21b7f0cff19. | 2.9% | — |
| CVE-2025-21197 | MED 6.5 | microsoft windows_10_1507 Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content. | 2.9% | — |
| CVE-2017-15695 | HIGH 8.8 | apache geode When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function. This allows remote code execution. Code deployment should be restrict | 2.9% | — |
| CVE-2014-0323 | MED 6.6 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow | 2.9% | — |
| CVE-2008-5025 | HIGH 7.8 | linux linux_kernel Stack-based buffer overflow in the hfs_cat_find_brec function in fs/hfs/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfs filesystem image with an invalid catalog namele | 2.9% | — |
| CVE-2017-3879 | MED 5.3 | cisco nx-os A Denial of Service vulnerability in the remote login functionality for Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause a process used for login to terminate unexpectedly and the login a | 2.9% | — |
| CVE-2017-3878 | MED 5.3 | cisco nx-os A Denial of Service vulnerability in the Telnet remote login functionality of Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause a Telnet process used for login to terminate unexpectedly an | 2.9% | — |
| CVE-2022-24541 | HIGH 8.8 | microsoft windows_10 Windows Server Service Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2011-1606 | HIGH 7.8 | cisco unified_communications_manager Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (process failure) via a | 2.9% | — |
| CVE-2011-1605 | HIGH 7.8 | cisco unified_communications_manager Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su2, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (process failure) via | 2.9% | — |
| CVE-2009-2866 | HIGH 7.8 | cisco ios Unspecified vulnerability in Cisco IOS 12.2 through 12.4 allows remote attackers to cause a denial of service (device reload) via a crafted H.323 packet, aka Bug ID CSCsz38104. | 2.9% | — |
| CVE-2009-2864 | HIGH 7.8 | cisco unified_callmanager Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x before 7.1(2) allows remote attackers to cause a denial of service (service restart) via malformed SIP messages, aka | 2.9% | — |
| CVE-2009-0636 | HIGH 7.8 | cisco ios Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when SIP voice services are enabled, allows remote attackers to cause a denial of service (device crash) via a valid SIP message. | 2.9% | — |
| CVE-2008-3816 | HIGH 7.8 | cisco adaptive_security_appliance_5500_series Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.2(4)9 and 7.2(4)10 allows remote attackers to cause a denial of service (device reload) via a crafted IPv6 packet. | 2.9% | — |
| CVE-2007-2414 | HIGH 7.8 | myserver myserver MyServer before 0.8.8 allows remote attackers to cause a denial of service via unspecified vectors. | 2.9% | — |
| CVE-2022-21988 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 2.9% | — |