57.020 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
57.020 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-7115 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure | 2.7% | — |
| CVE-2019-7114 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure | 2.7% | — |
| CVE-2017-12219 | HIGH 7.5 | cisco spa_301_firmware A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) conditio | 2.7% | — |
| CVE-2016-9225 | HIGH 8.6 | cisco asa_cx_context-aware_security_software A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an unauthenticated, remote attacker to cause the CX module to be unable to process further traffic, resulting in a | 2.7% | — |
| CVE-2015-0095 | MED 5.6 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to cause a denial of serv | 2.7% | — |
| CVE-2023-48782 | HIGH 8.8 | fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters | 2.7% | — |
| CVE-2022-21878 | HIGH 7.8 | microsoft windows_10 Windows Geolocation Service Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2020-10110 | MED 5.3 | citrix gateway_firmware Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and | 2.7% | — |
| CVE-2012-2287 | HIGH 8.5 | emc rsa_authentication_agent The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an unspecified configuration exists, allows remote authenticated users to bypass an intended token-authentication | 2.7% | — |
| CVE-2023-36034 | HIGH 7.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-31958 | HIGH 7.5 | microsoft windows_10 Windows NTLM Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2018-8428 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.7% | — |
| CVE-2009-1157 | HIGH 7.8 | cisco adaptive_security_appliance_5500 Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)30, 8.0 before 8.0(4)28, and 8.1 before 8.1(2)19 allows remote attackers to cause a denial of service (mem | 2.7% | — |
| CVE-2022-38450 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue req | 2.7% | — |
| CVE-2022-29109 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2020-2014 | HIGH 8.8 | paloaltonetworks pan-os An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; P | 2.7% | — |
| CVE-2018-11777 | HIGH 8.1 | apache hive In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use. | 2.7% | — |
| CVE-2008-4618 | HIGH 7.8 | linux linux_kernel The Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.27 does not properly handle a protocol violation in which a parameter has an invalid length, which allows attackers to cause a denial of service (panic) via unspecifi | 2.7% | — |
| CVE-2020-9568 | HIGH 7.8 | adobe bridge Adobe Bridge versions 10.0.1 and earlier version have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution . | 2.7% | — |
| CVE-2010-1734 | MED 4.9 | microsoft windows_2000 The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call fo | 2.7% | — |
| CVE-2024-38126 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.7% | — |
| CVE-2016-1365 | HIGH 8.8 | cisco application_policy_infrastructure_controller_enterprise_module The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users to execute arbitrary commands as root via a crafted upgrade parameter, aka Bug ID CSCux15507. | 2.7% | — |
| CVE-2010-4258 | MED 6.2 | fedoraproject fedora The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by | 2.7% | — |
| CVE-2023-36010 | HIGH 7.5 | microsoft malware_protection_platform Microsoft Defender Denial of Service Vulnerability | 2.7% | — |
| CVE-2022-28824 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by a Use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in tha | 2.7% | — |