IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-21613 MED 5.5 adobe acrobat Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabi 2.5%
CVE-2017-9458 CRIT 9.8 paloaltonetworks pan-os XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive inform 2.5%
CVE-2024-35252 HIGH 7.5 microsoft azure_storage_data_movement_library Azure Storage Movement Client Library Denial of Service Vulnerability 2.5%
CVE-2021-24082 MED 4.3 microsoft windows_10 Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability 2.5%
CVE-2019-1873 HIGH 8.6 cisco asa_5506-x_firmware A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reboot unexpectedly. The vulnerability is due to 2.5%
CVE-2017-7336 CRIT 9.8 fortinet fortiwlm A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges. 2.5%
CVE-2023-38157 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability 2.5%
CVE-2020-1173 MED 6.8 microsoft power_bi_report_server A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially crafted payload and sending it to the user. 2.5%
CVE-1999-0585 LOW 2.1 microsoft windows_2000 A Windows NT administrator account has the default name of Administrator. 2.5%
CVE-2022-30188 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2.5%
CVE-2022-30179 HIGH 7.8 microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability 2.5%
CVE-2022-29111 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2.5%
CVE-2017-5055 HIGH 8.8 google chrome A use after free in printing in Google Chrome prior to 57.0.2987.133 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. 2.5%
CVE-2024-22393 CRIT 9.1 apache answer Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by upl 2.5%
CVE-2021-39858 LOW 3.3 adobe acrobat Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the curre 2.5%
CVE-2021-26472 CRIT 10.0 vembu bdr_suite In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using this command argument an unauthenticated attacker can execute arbitrary OS commands with SYSTEM privileges. 2.5%
CVE-2018-1426 HIGH 7.4 ibm db2 IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple ICC instances are loaded which could result in duplicate Session IDs and a risk of duplicate key material. IBM X-Force 2.5%
CVE-2010-1965 HIGH 7.5 hp insight_orchestration Unspecified vulnerability in HP Insight Orchestration for Windows before 6.1 allows remote attackers to read or modify data via unknown vectors. 2.5%
CVE-2023-36395 HIGH 7.5 microsoft windows_server_2008 Windows Deployment Services Denial of Service Vulnerability 2.5%
CVE-2023-36392 HIGH 7.5 microsoft windows_server_2012 DHCP Server Service Denial of Service Vulnerability 2.5%
CVE-2023-36786 HIGH 7.2 microsoft skype_for_business_server Skype for Business Remote Code Execution Vulnerability 2.5%
CVE-2021-44743 HIGH 7.8 adobe bridge Adobe Bridge version 11.1.2 (and earlier) and version 12.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction 2.5%
CVE-2020-1926 MED 5.9 apache hive Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8 2.5%
CVE-2019-9969 HIGH 7.8 xnview xnview_classic XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x385399. 2.5%
CVE-2018-1289 HIGH 8.8 apache fineract In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' and 'sortOrder' which are appended directly with SQL statem 2.5%