57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-21613 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabi | 2.5% | — |
| CVE-2017-9458 | CRIT 9.8 | paloaltonetworks pan-os XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive inform | 2.5% | — |
| CVE-2024-35252 | HIGH 7.5 | microsoft azure_storage_data_movement_library Azure Storage Movement Client Library Denial of Service Vulnerability | 2.5% | — |
| CVE-2021-24082 | MED 4.3 | microsoft windows_10 Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability | 2.5% | — |
| CVE-2019-1873 | HIGH 8.6 | cisco asa_5506-x_firmware A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reboot unexpectedly. The vulnerability is due to | 2.5% | — |
| CVE-2017-7336 | CRIT 9.8 | fortinet fortiwlm A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges. | 2.5% | — |
| CVE-2023-38157 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 2.5% | — |
| CVE-2020-1173 | MED 6.8 | microsoft power_bi_report_server A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially crafted payload and sending it to the user. | 2.5% | — |
| CVE-1999-0585 | LOW 2.1 | microsoft windows_2000 A Windows NT administrator account has the default name of Administrator. | 2.5% | — |
| CVE-2022-30188 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2022-30179 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2022-29111 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2017-5055 | HIGH 8.8 | google chrome A use after free in printing in Google Chrome prior to 57.0.2987.133 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | 2.5% | — |
| CVE-2024-22393 | CRIT 9.1 | apache answer Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by upl | 2.5% | — |
| CVE-2021-39858 | LOW 3.3 | adobe acrobat Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the curre | 2.5% | — |
| CVE-2021-26472 | CRIT 10.0 | vembu bdr_suite In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using this command argument an unauthenticated attacker can execute arbitrary OS commands with SYSTEM privileges. | 2.5% | — |
| CVE-2018-1426 | HIGH 7.4 | ibm db2 IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple ICC instances are loaded which could result in duplicate Session IDs and a risk of duplicate key material. IBM X-Force | 2.5% | — |
| CVE-2010-1965 | HIGH 7.5 | hp insight_orchestration Unspecified vulnerability in HP Insight Orchestration for Windows before 6.1 allows remote attackers to read or modify data via unknown vectors. | 2.5% | — |
| CVE-2023-36395 | HIGH 7.5 | microsoft windows_server_2008 Windows Deployment Services Denial of Service Vulnerability | 2.5% | — |
| CVE-2023-36392 | HIGH 7.5 | microsoft windows_server_2012 DHCP Server Service Denial of Service Vulnerability | 2.5% | — |
| CVE-2023-36786 | HIGH 7.2 | microsoft skype_for_business_server Skype for Business Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-44743 | HIGH 7.8 | adobe bridge Adobe Bridge version 11.1.2 (and earlier) and version 12.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 2.5% | — |
| CVE-2020-1926 | MED 5.9 | apache hive Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8 | 2.5% | — |
| CVE-2019-9969 | HIGH 7.8 | xnview xnview_classic XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x385399. | 2.5% | — |
| CVE-2018-1289 | HIGH 8.8 | apache fineract In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' and 'sortOrder' which are appended directly with SQL statem | 2.5% | — |