56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.959 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-30310 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a | 2.8% | — |
| CVE-2022-35841 | HIGH 8.8 | microsoft windows_10 Windows Enterprise App Management Service Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2014-0509 | MED 4.3 | adobe adobe_air Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adob | 2.8% | — |
| CVE-2022-24539 | HIGH 8.1 | microsoft windows_server_2016 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability | 2.8% | — |
| CVE-2021-24101 | MED 6.5 | microsoft dynamics_365 Microsoft Dataverse Information Disclosure Vulnerability | 2.8% | — |
| CVE-2017-3812 | MED 6.8 | cisco industrial_ethernet_2000_series_firmware A vulnerability in the implementation of Common Industrial Protocol (CIP) functionality in Cisco Industrial Ethernet 2000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to a system memory leak. | 2.8% | — |
| CVE-2021-26559 | MED 6.5 | apache airflow Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg` | 2.8% | — |
| CVE-2017-3820 | MED 6.5 | cisco ios_xe A vulnerability in Simple Network Management Protocol (SNMP) functions of Cisco ASR 1000 Series Aggregation Services Routers running Cisco IOS XE Software Release 3.13.6S, 3.16.2S, or 3.17.1S could allow an authenticated, remote attacker to cause high CPU usag | 2.8% | — |
| CVE-2021-34551 | HIGH 8.1 | fedoraproject fedora PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname. | 2.8% | — |
| CVE-2019-12413 | MED 5.3 | apache superset In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query. | 2.8% | — |
| CVE-2018-14641 | MED 6.5 | linux linux_kernel A security flaw was found in the ip_frag_reasm() function in net/ipv4/ip_fragment.c in the Linux kernel from 4.19-rc1 to 4.19-rc3 inclusive, which can cause a later system crash in ip_do_fragment(). With certain non-default, but non-rare, configuration of a vi | 2.8% | — |
| CVE-2013-1405 | HIGH 10.0 | vmware esx VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properl | 2.8% | — |
| CVE-2023-36566 | MED 6.5 | microsoft common_data_model_sdk Microsoft Common Data Model SDK Denial of Service Vulnerability | 2.8% | — |
| CVE-2022-26934 | MED 6.5 | microsoft 365_apps Windows Graphics Component Information Disclosure Vulnerability | 2.8% | — |
| CVE-2020-1473 | HIGH 7.0 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 2.8% | — |
| CVE-2012-5978 | MED 5.0 | vmware view Multiple directory traversal vulnerabilities in the (1) View Connection Server and (2) View Security Server in VMware View 4.x before 4.6.2 and 5.x before 5.1.2 allow remote attackers to read arbitrary files via unspecified vectors. | 2.8% | — |
| CVE-2012-5051 | MED 5.0 | vmware capacityiq Directory traversal vulnerability in VMware CapacityIQ 1.5.x allows remote attackers to read arbitrary files via unspecified vectors. | 2.8% | — |
| CVE-2020-24414 | HIGH 7.8 | adobe illustrator Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability require | 2.8% | — |
| CVE-2020-24413 | HIGH 7.8 | adobe illustrator Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability require | 2.8% | — |
| CVE-2020-24412 | HIGH 7.8 | adobe illustrator Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability require | 2.8% | — |
| CVE-2019-8237 | CRIT 9.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an insufficiently robust encryption vulnerability. | 2.8% | — |
| CVE-2019-3772 | CRIT 9.8 | oracle retail_customer_management_and_segmentation_foundation Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources. | 2.8% | — |
| CVE-2016-1297 | HIGH 8.8 | cisco application_control_engine_software The Device Manager GUI in Cisco Application Control Engine (ACE) 4710 A5 before A5(3.1) allows remote authenticated users to bypass intended RBAC restrictions and execute arbitrary CLI commands with admin privileges via an unspecified parameter in a POST reque | 2.8% | — |
| CVE-2013-0997 | MED 6.8 | apple itunes WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.8% | — |
| CVE-2020-3279 | HIGH 7.2 | cisco rv016_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu | 2.8% | — |