57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-0562 | MED 4.3 | adobe acrobat Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)." | 2.5% | — |
| CVE-2012-1517 | HIGH 9.0 | vmware esx The VMX process in VMware ESXi 4.1 and ESX 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrite and process crash) or possibly execute arbitrary code on the host OS via vectors involving function | 2.5% | — |
| CVE-2024-38146 | HIGH 7.5 | microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | 2.5% | — |
| CVE-2024-38145 | HIGH 7.5 | microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | 2.5% | — |
| CVE-2018-1258 | HIGH 8.8 | netapp oncommand_insight Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted. | 2.5% | — |
| CVE-2015-2529 | LOW 2.1 | microsoft windows_10 The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Kernel ASLR Bypass Vulnerability." | 2.5% | — |
| CVE-2013-6968 | MED 5.0 | cisco webex_training_center Cisco WebEx Training Center provides different error messages for registration attempts depending on whether the e-mail address exists, which allows remote attackers to enumerate attendees via a series of requests, aka Bug ID CSCul36003. | 2.5% | — |
| CVE-2024-38474 | CRIT 9.8 | apache http_server Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be execu | 2.5% | — |
| CVE-2015-4299 | MED 5.5 | cisco unified_web_and_e-mail_interaction_manager Cisco Unified Web and E-Mail Interaction Manager 9.0(2) improperly performs authorization, which allows remote authenticated users to remove default messaging-queue system folders via unspecified vectors, aka Bug ID CSCuo89046. | 2.5% | — |
| CVE-2015-4298 | MED 6.5 | cisco unified_web_and_e-mail_interaction_manager Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056. | 2.5% | — |
| CVE-2017-10615 | CRIT 9.8 | juniper junos A vulnerability in the pluggable authentication module (PAM) of Juniper Networks Junos OS may allow an unauthenticated network based attacker to potentially execute arbitrary code or crash daemons such as telnetd or sshd that make use of PAM. Affected Juniper | 2.5% | — |
| CVE-2017-3021 | LOW 3.3 | adobe acrobat Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser engine. | 2.5% | — |
| CVE-2023-29179 | MED 6.5 | fortinet fortios A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 allows attacker to denial of service via specially crafted HTTP requests. | 2.5% | — |
| CVE-2019-1091 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Unistore.dll fails to properly handle objects in memory, aka 'Microsoft unistore.dll Information Disclosure Vulnerability'. | 2.5% | — |
| CVE-2016-4926 | CRIT 9.8 | juniper junos_space Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based users with access to Junos Space web interface to perform certain administrative tasks without authentication. | 2.5% | — |
| CVE-2015-3251 | MED 4.9 | apache cloudstack Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API calls. | 2.5% | — |
| CVE-2008-2061 | HIGH 7.8 | cisco unified_communications_manager The Computer Telephony Integration (CTI) Manager service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3c) and 6.x before 6.1(2) allows remote attackers to cause a denial of service (TSP crash) via malformed network traffic to TCP port 2748. | 2.5% | — |
| CVE-2008-1748 | HIGH 7.8 | cisco unified_communications_manager Cisco Unified Communications Manager 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) does not properly validate SIP URLs, which allows remote attackers to cause a denial of service (service interruption) | 2.5% | — |
| CVE-2008-1747 | HIGH 7.8 | cisco unified_communications_manager Unspecified vulnerability in Cisco Unified Communications Manager 4.1 before 4.1(3)SR6, 4.2 before 4.2(3)SR3, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) allows remote attackers to cause a denial of service (CCM service restart) via an unspecif | 2.5% | — |
| CVE-2022-35671 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.30249 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabi | 2.5% | — |
| CVE-2021-1586 | HIGH 8.6 | cisco nx-os A vulnerability in the Multi-Pod or Multi-Site network configurations for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to unexpectedly restart the device, resulting in | 2.5% | — |
| CVE-2019-12629 | HIGH 7.2 | cisco sd-wan_firmware A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is due to insufficient input validation of da | 2.5% | — |
| CVE-2004-1322 | HIGH 7.5 | cisco unity_server Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages. | 2.5% | — |
| CVE-2021-27055 | HIGH 7.0 | microsoft 365_apps Microsoft Visio Security Feature Bypass Vulnerability | 2.5% | — |
| CVE-2012-5424 | MED 5.0 | cisco secure_access_control_server Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7, when a certain configuration involving TACACS+ and LDAP is used, does not properly validate passwords, which allows remote attackers to bypass authentication by sendin | 2.5% | — |