56.950 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.950 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-8184 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to i | 2.9% | — |
| CVE-2019-8182 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to i | 2.9% | — |
| CVE-2019-8168 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to i | 2.9% | — |
| CVE-2019-8164 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to i | 2.9% | — |
| CVE-2004-1235 | MED 6.2 | avaya converged_communications_server Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor. | 2.9% | — |
| CVE-2026-44825 | HIGH 8.1 | apache solr Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials instal | 2.9% | — |
| CVE-2024-21319 | MED 6.8 | microsoft .net Microsoft Identity Denial of service vulnerability | 2.9% | — |
| CVE-2021-26439 | MED 4.6 | microsoft edge Microsoft Edge for Android Information Disclosure Vulnerability | 2.9% | — |
| CVE-2019-0636 | MED 5.5 | microsoft windows_10 An information vulnerability exists when Windows improperly discloses file information, aka 'Windows Information Disclosure Vulnerability'. | 2.9% | — |
| CVE-2015-5516 | HIGH 7.5 | f5 big-ip_access_policy_manager Memory leak in the last hop kernel module in F5 BIG-IP LTM, GTM, and Link Controller 10.1.x, 10.2.x before 10.2.4 HF13, 11.x before 11.2.1 HF15, 11.3.x, 11.4.x, 11.5.x before 11.5.3 HF2, and 11.6.x before HF6, BIG-IP AAM 11.4.x, 11.5.x before 11.5.3 HF2 and 11 | 2.9% | — |
| CVE-2022-39947 | HIGH 8.8 | fortinet fortiadc A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiADC version 6.2.0 through 6.2.3, FortiADC version version 6.1.0 through 6.1.6, FortiADC version 6.0.0 through 6. | 2.9% | — |
| CVE-2015-0713 | HIGH 9.0 | cisco telepresence_advanced_media_gateway The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2(1.94 | 2.9% | — |
| CVE-2008-0531 | HIGH 9.3 | cisco session_initiation_protocol_\(sip\)_firmware Heap-based buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote SIP servers to execute arbitrary code via a crafted challenge/response message. | 2.9% | — |
| CVE-2019-1703 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulti | 2.9% | — |
| CVE-2017-12608 | HIGH 7.8 | apache openoffice A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in a | 2.9% | — |
| CVE-2007-5552 | HIGH 9.3 | cisco ios Integer overflow in Cisco IOS allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is | 2.9% | — |
| CVE-2005-4635 | MED 5.0 | linux linux_kernel The nl_fib_input function in fib_frontend.c in the Linux kernel before 2.6.15 does not check for valid lengths of the header and payload, which allows remote attackers to cause a denial of service (invalid memory reference) via malformed fib_lookup netlink mes | 2.9% | — |
| CVE-1999-0700 | MED 6.2 | microsoft windows_2000 Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file. | 2.9% | — |
| CVE-2021-24099 | MED 6.5 | microsoft lync_server Skype for Business and Lync Denial of Service Vulnerability | 2.9% | — |
| CVE-2020-3284 | CRIT 9.8 | cisco a99-rp2-se_firmware A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could allow an unauthenticated, remote attacker to execute unsigned code during the PXE boot process on an affected device. The PXE boot loader is | 2.9% | — |
| CVE-2018-0048 | HIGH 7.5 | juniper junos A vulnerability in the Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support can allow a network based unauthenticated attacker to cause a severe memory exhaustion condition on the device. This can have an adverse impact on the system per | 2.9% | — |
| CVE-2016-1472 | HIGH 7.5 | cisco small_business_220_series_smart_plus_switches The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of service (interface outage) via a crafted HTTP request, aka Bug ID CSCuz76238. | 2.9% | — |
| CVE-2014-5239 | MED 4.0 | microsoft outlook.com The Microsoft Outlook.com application before 7.8.2.12.49.7090 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2.9% | — |
| CVE-2021-42295 | MED 5.5 | microsoft 365_apps Visual Basic for Applications Information Disclosure Vulnerability | 2.9% | — |
| CVE-2017-3105 | MED 6.1 | adobe robohelp Adobe RoboHelp has an Open Redirect vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2. | 2.9% | — |