56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.959 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-27261 | HIGH 7.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 2.7% | — |
| CVE-2021-24077 | CRIT 9.8 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2016-9208 | MED 6.5 | cisco emergency_responder A vulnerability in the File Management Utility, the Download File form, and the Serviceability application of Cisco Emergency Responder could allow an authenticated, remote attacker to access files in arbitrary locations on the file system of an affected devic | 2.7% | — |
| CVE-2015-6319 | CRIT 9.8 | cisco rv_series_router_firmware SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to execute arbitrary SQL commands via a crafted header in an HTTP request, aka Bug ID CSCuv29574. | 2.7% | — |
| CVE-2022-25329 | CRIT 9.8 | trendmicro serverprotect Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to | 2.7% | — |
| CVE-2022-21913 | MED 5.3 | microsoft windows_10 Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass | 2.7% | — |
| CVE-2018-0170 | HIGH 7.5 | cisco ios_xe A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition, related to the OpenDNS software. The vulnerability is due to a logic error that exi | 2.7% | — |
| CVE-2018-0157 | HIGH 8.6 | cisco ios_xe A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a device to reload. The vulnerability is due to the way fragmented packets are handled in the firewall code. An attacker could exp | 2.7% | — |
| CVE-2025-21230 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.7% | — |
| CVE-2019-12397 | MED 6.1 | apache ranger Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix. | 2.7% | — |
| CVE-2007-1209 | HIGH 7.2 | microsoft windows_vista Use-after-free vulnerability in the Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista does not properly handle connection resources when starting and stopping processes, which allows local users to gain privileges by opening and closing multi | 2.7% | — |
| CVE-2001-1105 | HIGH 7.5 | cisco icdn RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure. | 2.7% | — |
| CVE-2019-18190 | CRIT 9.8 | trendmicro antivirus\+_security_2020 Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances. | 2.7% | — |
| CVE-2018-17193 | MED 6.1 | apache nifi The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache Ni | 2.7% | — |
| CVE-2021-31446 | LOW 3.3 | foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious f | 2.7% | — |
| CVE-2020-8269 | HIGH 8.8 | citrix virtual_apps_and_desktops An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9 | 2.7% | — |
| CVE-2018-17192 | MED 6.5 | apache nifi The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently appl | 2.7% | — |
| CVE-2002-0046 | MED 5.0 | linux linux_kernel Linux kernel, and possibly other operating systems, allows remote attackers to read portions of memory via a series of fragmented ICMP packets that generate an ICMP TTL Exceeded response, which includes portions of the memory in the response packet. | 2.7% | — |
| CVE-2021-26861 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2016-4968 | MED 6.5 | fortinet fortiwan The linkreport/tmp/admin_global page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to discover administrator cookies via a GET request. | 2.7% | — |
| CVE-2006-3287 | HIGH 7.5 | cisco wireless_control_system Cisco Wireless Control System (WCS) for Linux and Windows 4.0(1) and earlier uses a default administrator username "root" and password "public," which allows remote attackers to gain access (aka bug CSCse21391). | 2.7% | — |
| CVE-2006-3286 | HIGH 7.5 | cisco wireless_control_system The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(63) stores a hard-coded username and password in plaintext within unspecified files, which allows remote authenticated users to access the database (aka bug CSCsd1595 | 2.7% | — |
| CVE-2006-3285 | HIGH 7.5 | cisco wireless_control_system The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) uses an undocumented, hard-coded username and password, which allows remote authenticated users to read, and possibly modify, sensitive configuration data (aka bu | 2.7% | — |
| CVE-2025-13316 | HIGH 8.1 | lynxtechnology twonky_server Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and | 2.7% | — |
| CVE-2021-40485 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.7% | — |