IT
56.950 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.950 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-28571 HIGH 8.3 adobe after_effects Adobe After Effects version 18.1 (and earlier) is affected by a potential Command injection vulnerability when chained with a development and debugging tool for JavaScript scripts. An unauthenticated attacker could leverage this vulnerability to achieve arbitr 2.9%
CVE-2020-3800 HIGH 7.5 adobe acrobat_dc Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have a memory address leak vulnerability. Successful exploitation could lead to inf 2.9%
CVE-2024-43483 HIGH 7.5 microsoft .net .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability 2.9%
CVE-2020-9618 MED 5.5 adobe audition Adobe Audition versions 13.0.5 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. 2.9%
CVE-2022-42339 HIGH 7.8 adobe acrobat Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue req 2.9%
CVE-2021-1337 HIGH 7.2 cisco rv016_multi-wan_vpn_router_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpect 2.9%
CVE-2020-36278 HIGH 7.5 debian debian_linux Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c. 2.9%
CVE-2020-9491 HIGH 7.5 apache nifi In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communication such as cluster request replication 2.9%
CVE-2012-1821 MED 5.0 symantec endpoint_protection The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.700x on Windows Server 2003 allows remote attackers to cause a denial of service (web-server outage, or daemon crash or hang) via a flood 2.9%
CVE-2017-0241 MED 5.3 microsoft edge An elevation of privilege vulnerability exists when Microsoft Edge renders a domain-less page in the URL, which could allow Microsoft Edge to perform actions in the context of the Intranet Zone and access functionality that is not typically available to the br 2.9%
CVE-2020-10515 CRIT 9.8 starface unified_communication_\&_collaboration_client STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006. 2.9%
CVE-2016-6379 HIGH 7.5 cisco ios Cisco IOS 12.2 and IOS XE 3.14 through 3.16 and 16.1 allow remote attackers to cause a denial of service (device reload) via crafted IP Detail Record (IPDR) packets, aka Bug ID CSCuu35089. 2.9%
CVE-2016-6386 HIGH 7.5 cisco ios_xe Cisco IOS XE 3.1 through 3.17 and 16.1 on 64-bit platforms allows remote attackers to cause a denial of service (data-structure corruption and device reload) via fragmented IPv4 packets, aka Bug ID CSCux66005. 2.9%
CVE-2016-6355 HIGH 7.5 cisco ios_xr Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows remote attackers to cause a denial of service (control-plane protocol outage) via crafted fragmented packets, aka Bug ID CSCux26791. 2.9%
CVE-2016-1466 HIGH 7.5 cisco unified_communications_manager_im_and_presence_service Cisco Unified Communications Manager IM and Presence Service 9.1(1) SU6, 9.1(1) SU6a, 9.1(1) SU7, 10.5(2) SU2, 10.5(2) SU2a, 11.0(1) SU1, and 11.5(1) allows remote attackers to cause a denial of service (sipd process restart) via crafted headers in a SIP packe 2.9%
CVE-2016-1312 HIGH 7.5 cisco asa_5500_csc-ssm_firmware The HTTPS inspection engine in the Content Security and Control Security Services Module (CSC-SSM) 6.6 before 6.6.1164.0 for Cisco ASA 5500 devices allows remote attackers to cause a denial of service (memory consumption or device reload) via a flood of HTTPS 2.9%
CVE-2018-0745 MED 4.7 microsoft windows_10 The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Windows Information Disclosure Vulnerability". This CVE I 2.9%
CVE-2015-6531 HIGH 7.8 paloaltonetworks pan-os Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file. 2.9%
CVE-2023-29324 MED 6.5 microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability 2.9%
CVE-2023-28293 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 2.9%
CVE-2020-36281 HIGH 7.5 debian debian_linux Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c. 2.9%
CVE-2020-17120 MED 5.3 microsoft sharepoint_foundation Microsoft SharePoint Information Disclosure Vulnerability 2.9%
CVE-2020-3144 CRIT 9.8 cisco rv110w_firmware A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass authenti 2.9%
CVE-2020-1936 MED 6.1 apache ambari A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4. 2.9%
CVE-2026-55957 HIGH 7.3 apache tomcat Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0- 2.9%