57.020 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
57.020 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-31209 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 2.6% | — |
| CVE-2005-2827 | HIGH 7.2 | microsoft windows_2000 The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory and execution flow via steps in which a terminating thread causes Asynchronous Procedure Call (APC) entries to free the wrong dat | 2.6% | — |
| CVE-2005-3273 | MED 5.0 | linux linux_kernel The rose_rt_ioctl function in rose_route.c for Radionet Open Source Environment (ROSE) in Linux 2.6 kernels before 2.6.12, and 2.4 before 2.4.29, does not properly verify the ndigis argument for a new route, which allows attackers to trigger array out-of-bound | 2.6% | — |
| CVE-2004-0949 | MED 6.4 | linux linux_kernel The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 does not properly handle the re-assembly of fragmented packets correctly, which could allow remote samba servers to (1) read arbitrary kernel information or (2) raise | 2.6% | — |
| CVE-2021-34458 | CRIT 9.9 | microsoft windows_server_2016 Windows Kernel Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2015-4213 | MED 4.0 | cisco nx-os Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext passwords by leveraging the existence of a decryption mechanism, aka Bug ID CSCuu84391. | 2.6% | — |
| CVE-2021-26881 | HIGH 7.5 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2018-0311 | HIGH 7.5 | cisco firepower_extensible_operating_system A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affe | 2.6% | — |
| CVE-2015-5358 | HIGH 7.1 | juniper junos Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D35, 13.2X52 before 13.2X52-D25, 13.3 before 13.3R6, 14.1R3 before 1 | 2.6% | — |
| CVE-2010-0567 | MED 5.0 | cisco asa_5500 Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.1), 8.1 before 8.1(2.37), and 8.2 before 8.2(1.15); and Cisco PIX 500 Series Security Appliance; allows remote attackers | 2.6% | — |
| CVE-2007-3843 | MED 4.3 | linux linux_kernel The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing despite s | 2.6% | — |
| CVE-2007-0199 | MED 5.0 | cisco ios The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange." | 2.6% | — |
| CVE-2018-14242 | HIGH 8.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 2.6% | — |
| CVE-2018-11623 | HIGH 8.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 2.6% | — |
| CVE-2024-30019 | MED 6.5 | microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability | 2.6% | — |
| CVE-2024-30011 | MED 6.5 | microsoft windows_server_2012 Windows Hyper-V Denial of Service Vulnerability | 2.6% | — |
| CVE-2020-3440 | MED 6.5 | cisco webex_meetings A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an unauthenticated, remote attacker to overwrite arbitrary files on an end-user system. The vulnerability is due to improper validation of URL parameters that are sent from a website t | 2.6% | — |
| CVE-2016-6811 | HIGH 8.8 | apache hadoop In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user. | 2.6% | — |
| CVE-2008-1286 | HIGH 7.8 | sun java_web_console Unspecified vulnerability in Sun Java Web Console 3.0.2, 3.0.3, and 3.0.4 allows remote attackers to bypass intended access restrictions and determine the existence of files or directories via unknown vectors. | 2.6% | — |
| CVE-2023-26417 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in | 2.6% | — |
| CVE-2018-0447 | MED 5.3 | cisco email_security_appliance A vulnerability in the anti-spam protection mechanisms of Cisco AsyncOS Software for the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass certain content filters on an affected device. The vulnerability is due to i | 2.6% | — |
| CVE-2017-7160 | HIGH 8.8 | apple icloud An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKi | 2.6% | — |
| CVE-2011-2338 | HIGH 7.6 | apple itunes WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other | 2.6% | — |
| CVE-2000-0289 | MED 5.0 | debian debian_linux IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection. | 2.6% | — |
| CVE-2021-21063 | HIGH 7.8 | adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Memory corruption vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker could lever | 2.6% | — |