56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.959 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-41038 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2019-1710 | CRIT 9.8 | cisco ios_xr A vulnerability in the sysadmin virtual machine (VM) on Cisco ASR 9000 Series Aggregation Services Routers running Cisco IOS XR 64-bit Software could allow an unauthenticated, remote attacker to access internal applications running on the sysadmin VM. The vuln | 2.8% | — |
| CVE-2018-4262 | HIGH 8.8 | apple icloud In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling. | 2.8% | — |
| CVE-2010-4680 | HIGH 9.0 | cisco 5500_series_adaptive_security_appliance The WebVPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) permits the viewing of CIFS shares even when CIFS file browsing has been disabled, which allows remote authenticated users to bypass intended | 2.8% | — |
| CVE-2010-4675 | HIGH 9.0 | cisco 5500_series_adaptive_security_appliance Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not properly determine the interfaces for which TELNET connections should be permitted, which allows remote authenticated users to bypass intended access restrictions v | 2.8% | — |
| CVE-2009-1808 | MED 4.9 | microsoft windows_xp Microsoft Windows XP SP3 allows local users to cause a denial of service (system crash) by making an SPI_SETDESKWALLPAPER SystemParametersInfo call with an improperly terminated pvParam argument, followed by an SPI_GETDESKWALLPAPER SystemParametersInfo call. | 2.8% | — |
| CVE-2009-0634 | HIGH 7.1 | cisco cisco_ios Multiple unspecified vulnerabilities in the home agent (HA) implementation in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interf | 2.8% | — |
| CVE-2021-42293 | MED 6.5 | microsoft 365_apps Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2025-55694 | HIGH 7.8 | microsoft windows_11_24h2 Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | 2.8% | — |
| CVE-2022-24519 | MED 6.5 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2022-24518 | MED 6.5 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2022-24506 | MED 6.5 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2021-34453 | HIGH 7.5 | microsoft exchange_server Microsoft Exchange Server Denial of Service Vulnerability | 2.8% | — |
| CVE-2020-1343 | MED 5.9 | microsoft visual_studio_live_share An information disclosure vulnerability exists in Visual Studio Code Live Share Extension when it exposes tokens in plain text, aka 'Visual Studio Code Live Share Information Disclosure Vulnerability'. | 2.8% | — |
| CVE-2020-4343 | HIGH 7.8 | ibm i2_analysts_notebook IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to execu | 2.8% | — |
| CVE-2002-0366 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry. | 2.8% | — |
| CVE-2018-4232 | MED 4.3 | apple icloud An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKi | 2.8% | — |
| CVE-2021-42009 | MED 4.3 | apache traffic_control An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a specially-crafted email subject to the /deliveryservices/request Traffic Ops endpoint to send an email, from the Traffic Ops server, with an arbitra | 2.8% | — |
| CVE-2019-12398 | MED 4.8 | apache airflow In Apache Airflow before 1.10.5 when running with the "classic" UI, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. The new "RBAC" UI is unaffected. | 2.8% | — |
| CVE-2013-4246 | HIGH 8.8 | apache subversion libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories and cause a denial of service or obtain sensitive information by editing packed revision properties. | 2.8% | — |
| CVE-2017-2972 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion module related to JPEG parsing. Successful exploitation could lead to arbitrary co | 2.8% | — |
| CVE-2015-4928 | MED 4.3 | apache ambari Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, includes cleartext passwords on a Configs screen, which allows physically proximate attackers to obtain sensitive information by reading password fields. | 2.8% | — |
| CVE-2014-3352 | MED 4.3 | cisco cloud_portal Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, related to an | 2.8% | — |
| CVE-2023-36003 | MED 6.7 | microsoft windows_10_1507 XAML Diagnostics Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2021-43905 | CRIT 9.6 | microsoft 365_copilot Microsoft Office app Remote Code Execution Vulnerability | 2.8% | — |