57.020 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
57.020 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2011-0117 | HIGH 7.6 | apple itunes WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability | 2.6% | — |
| CVE-2011-0114 | HIGH 7.6 | apple itunes WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability | 2.6% | — |
| CVE-2011-0113 | HIGH 7.6 | apple itunes WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability | 2.6% | — |
| CVE-2011-0112 | HIGH 7.6 | apple itunes WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability | 2.6% | — |
| CVE-2011-0111 | HIGH 7.6 | apple itunes WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability | 2.6% | — |
| CVE-2011-0376 | HIGH 10.0 | cisco telepresence_system_1000 The TFTP implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x, 1.6.0, and 1.6.1 allows remote attackers to obtain sensitive information via a GET request, aka Bug ID CSCte43876. | 2.6% | — |
| CVE-2010-0140 | HIGH 10.0 | cisco unified_meetingplace Multiple unspecified vulnerabilities in the web server in Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.3, and possibly 5 allow remote attackers to create (1) user or (2) administrator accounts via a crafted URL in a request to the i | 2.6% | — |
| CVE-2023-39508 | HIGH 8.8 | apache airflow Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It | 2.6% | — |
| CVE-2018-5703 | CRIT 9.8 | linux linux_kernel The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.14.11 allows attackers to cause a denial of service (slab out-of-bounds write) or possibly have unspecified other impact via vectors involving TLS. | 2.6% | — |
| CVE-2024-20676 | HIGH 8.0 | microsoft azure_storage_mover Azure Storage Mover Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2023-3466 | HIGH 8.3 | citrix netscaler_application_delivery_controller Reflected Cross-Site Scripting (XSS) | 2.6% | — |
| CVE-2021-34727 | CRIT 9.8 | cisco ios_xe_sd-wan A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes | 2.6% | — |
| CVE-2021-28607 | HIGH 7.8 | adobe after_effects Adobe After Effects version 18.2 (and earlier) is affected by a heap corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current | 2.6% | — |
| CVE-2019-1864 | HIGH 8.8 | cisco integrated_management_controller_supervisor A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerab | 2.6% | — |
| CVE-2019-8035 | MED 4.3 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful ex | 2.6% | — |
| CVE-1999-0293 | HIGH 7.5 | cisco ios AAA authentication on Cisco systems allows attackers to execute commands without authorization. | 2.6% | — |
| CVE-2021-27092 | MED 6.8 | microsoft windows_10 Azure AD Web Sign-in Security Feature Bypass Vulnerability | 2.6% | — |
| CVE-2016-3310 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted appl | 2.6% | — |
| CVE-2015-4229 | MED 5.0 | cisco unified_communications_domain_manager The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsmweb URL, aka Bug ID CSCuq22589. | 2.6% | — |
| CVE-2015-4218 | MED 5.0 | cisco jabber The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information via a crafted value in a GET request, aka Bug IDs CSCuu65622 and CSCuu70858. | 2.6% | — |
| CVE-2015-4212 | MED 5.0 | cisco webex_meeting_center Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by discovering credentials, aka Bug ID CSCut17466. | 2.6% | — |
| CVE-2015-4194 | MED 5.0 | cisco webex_meeting_center The web-based administrative interface in Cisco WebEx Meeting Center provides different error messages for failed login attempts depending on whether the username exists or corresponds to a privileged account, which allows remote attackers to enumerate account | 2.6% | — |
| CVE-2010-2249 | MED 6.5 | apple iphone_os Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks. | 2.6% | — |
| CVE-2023-29331 | HIGH 7.5 | microsoft .net .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | 2.6% | — |
| CVE-2022-22010 | MED 4.4 | microsoft windows_10 Media Foundation Information Disclosure Vulnerability | 2.6% | — |