56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.959 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-30133 | CRIT 9.8 | microsoft windows_10 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-1385 | MED 6.5 | cisco ios A vulnerability in the Cisco IOx application hosting environment of multiple Cisco platforms could allow an authenticated, remote attacker to conduct directory traversal attacks and read and write files on the underlying operating system or host system. This v | 2.7% | — |
| CVE-2012-2945 | HIGH 7.5 | apache hadoop Hadoop 1.0.3 contains a symlink vulnerability. | 2.7% | — |
| CVE-2018-19449 | HIGH 7.8 | foxitsoftware foxit_pdf_sdk_activex A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API Doc.exportAsFDF is used. An attacker can leverage this to gain remote code execution. | 2.7% | — |
| CVE-2018-19444 | HIGH 7.8 | foxitsoftware foxit_pdf_sdk_activex A use after free in the TextBox field Validate action in IReader_ContentProvider can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031. An attacker can leverage this to gain remote code execution. Relative to CVE-2018- | 2.7% | — |
| CVE-2018-0136 | HIGH 8.6 | cisco ios_xr A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (ASR) 9000 Series could allow an unauthenticated, remote attacker to trigger a reload of one or more Trident-based line cards, resulting in a | 2.7% | — |
| CVE-2017-3864 | HIGH 8.6 | cisco ios A vulnerability in the DHCP client implementation of Cisco IOS (12.2, 12.4, and 15.0 through 15.6) and Cisco IOS XE (3.3 through 3.7) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability occurs during | 2.7% | — |
| CVE-2013-2757 | HIGH 7.5 | citrix cloudplatform Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C does not properly restrict access to VNC ports on the management network, which allows remote attackers to have unspecified impact via unknown vectors. | 2.7% | — |
| CVE-2022-28274 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this | 2.7% | — |
| CVE-2011-4087 | HIGH 7.5 | linux linux_kernel The br_parse_ip_options function in net/bridge/br_netfilter.c in the Linux kernel before 2.6.39 does not properly initialize a certain data structure, which allows remote attackers to cause a denial of service by leveraging connectivity to a network interface | 2.7% | — |
| CVE-2018-4188 | MED 6.5 | apple apple_tv An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKi | 2.7% | — |
| CVE-2008-3792 | HIGH 7.1 | linux linux_kernel net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4 does not verify that the SCTP-AUTH extension is enabled before proceeding with SCTP-AUTH API functions, which allows attackers to cause a de | 2.7% | — |
| CVE-2020-1937 | HIGH 8.8 | apache kylin Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries. | 2.7% | — |
| CVE-2010-1763 | HIGH 10.0 | apple itunes Unspecified vulnerability in WebKit in Apple iTunes before 9.2 on Windows has unknown impact and attack vectors, a different vulnerability than CVE-2010-1387 and CVE-2010-1769. | 2.7% | — |
| CVE-2021-38629 | MED 6.5 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability | 2.7% | — |
| CVE-2019-7138 | MED 6.5 | adobe bridge_cc Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.7% | — |
| CVE-2019-7136 | MED 6.5 | adobe bridge_cc Adobe Bridge CC versions 9.0.2 have an use after free vulnerability. Successful exploitation could lead to information disclosure. | 2.7% | — |
| CVE-2019-7135 | MED 6.5 | adobe bridge_cc Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.7% | — |
| CVE-2019-7134 | MED 6.5 | adobe bridge_cc Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.7% | — |
| CVE-2017-7663 | MED 6.1 | apache openmeetings Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0. | 2.7% | — |
| CVE-2021-40733 | HIGH 7.8 | adobe animate Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .psd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to | 2.7% | — |
| CVE-2020-3554 | HIGH 7.5 | cisco adaptive_security_appliance A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected devic | 2.7% | — |
| CVE-2020-1198 | HIGH 7.4 | microsoft sharepoint_enterprise_server <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially | 2.7% | — |
| CVE-2019-7081 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.7% | — |
| CVE-2018-1284 | LOW 3.7 | apache hive In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the content of a file on the machine running HiveServer2 owned by HiveSer | 2.7% | — |