56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.959 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-1006 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1005 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1004 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1003 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1002 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1001 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-1000 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2013-0999 | HIGH 9.3 | apple iphone_os WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than othe | 2.7% | — |
| CVE-2020-16933 | HIGH 7.0 | microsoft 365_apps <p>A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of | 2.7% | — |
| CVE-2008-2059 | HIGH 7.8 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 allows remote attackers to bypass control-plane ACLs for the device via unknown vectors. | 2.7% | — |
| CVE-2022-29131 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-29129 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-29128 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2020-1507 | HIGH 7.9 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system.</p> <p>To exploit the vulnerabi | 2.7% | — |
| CVE-2019-1043 | MED 6.4 | microsoft windows_10 A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successf | 2.7% | — |
| CVE-2016-7544 | HIGH 7.5 | cryptopp crypto\+\+ Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed. | 2.7% | — |
| CVE-2009-3760 | HIGH 7.5 | citrix xencenterweb Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these | 2.7% | — |
| CVE-1999-1235 | MED 4.6 | microsoft internet_explorer Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to | 2.7% | — |
| CVE-2020-1944 | CRIT 9.8 | apache traffic_server There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions. | 2.7% | — |
| CVE-2011-0817 | HIGH 10.0 | sun jdk Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, a | 2.7% | — |
| CVE-2008-1392 | HIGH 10.0 | vmware ace The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the console of the guest OS accessible through anonymous VIX API calls, which has unknown impact and attack vectors. | 2.7% | — |
| CVE-2018-3933 | HIGH 8.8 | antennahouse office_server_document_converter An exploitable out-of-bounds write exists in the Microsoft Word document conversion functionality of the Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312). A crafted Microsoft Word (DOC) document can lead to an out | 2.7% | — |
| CVE-2016-8746 | MED 5.9 | apache ranger Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true. | 2.7% | — |
| CVE-2026-62893 | CRIT 9.8 | microsoft windows_10_1607 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | 2.7% | — |
| CVE-2021-33740 | HIGH 7.8 | microsoft windows_10 Windows Media Remote Code Execution Vulnerability | 2.7% | — |