IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2008-1181 MED 5.0 juniper secure_access_2000 Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.cgi without certain parameters, which reveals the path in an "Execute failed" error message. 2.5%
CVE-2005-4849 MED 5.0 apache derby Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensiti 2.5%
CVE-2021-36016 LOW 3.3 adobe media_encoder Adobe Media Encoder version 15.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to read arbitrary file system information in the context of t 2.5%
CVE-2021-34489 HIGH 7.8 microsoft windows_10 DirectWrite Remote Code Execution Vulnerability 2.5%
CVE-2009-1168 HIGH 7.1 cisco ios Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 through 2.4.0; when RFC4 2.5%
CVE-2022-26901 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 2.4%
CVE-2021-26900 HIGH 7.8 microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability 2.4%
CVE-2024-43521 HIGH 7.5 microsoft windows_server_2012 Windows Hyper-V Denial of Service Vulnerability 2.4%
CVE-2021-34492 HIGH 8.1 microsoft windows_10 Windows Certificate Spoofing Vulnerability 2.4%
CVE-2017-7687 HIGH 7.5 apache mesos When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev might crash because the code accidentally calls inappropriate function. A malicious act 2.4%
CVE-2007-3756 MED 4.3 apple safari Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to obtain sensitive information via a crafted web page that identifies the URL of the parent window, even when the parent 2.4%
CVE-2021-32567 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. 2.4%
CVE-2020-24427 LOW 3.3 adobe acrobat Acrobat Reader versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an input validation vulnerability when decoding a crafted codec that could result in the disclosure of sensitive memory. An atta 2.4%
CVE-2019-19770 HIGH 8.2 linux linux_kernel In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_creat 2.4%
CVE-2018-19450 HIGH 7.8 foxitsoftware foxit_pdf_sdk_activex A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a launch action. An attacker can leverage this to gain remote code execution. 2.4%
CVE-2018-19445 HIGH 7.8 foxitsoftware foxit_pdf_sdk_activex A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API app.launchURL is used. An attacker can leverage this to gain remote code execution. 2.4%
CVE-2025-21351 HIGH 7.5 microsoft windows_10_1607 Windows Active Directory Domain Services API Denial of Service Vulnerability 2.4%
CVE-2024-38233 HIGH 7.5 microsoft windows_10_1607 Windows Networking Denial of Service Vulnerability 2.4%
CVE-2022-28256 MED 5.5 adobe acrobat Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to b 2.4%
CVE-2021-43899 CRIT 9.8 microsoft wireless_display_adapter_firmware Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability 2.4%
CVE-2015-2062 HIGH 7.2 huge-it huge-it_slider Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remote administrators to execute arbitrary SQL commands via the removeslide parameter in a popup_posts or edit_cat action in the sliders_huge_it 2.4%
CVE-2017-9790 HIGH 7.5 apache mesos When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev crashes if the request path is empty, because the parser assumes the request path always starts with ' 2.4%
CVE-2014-2106 HIGH 7.8 cisco ios Cisco IOS 15.3M before 15.3(3)M2 and IOS XE 3.10.xS before 3.10.2S allow remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCug45898. 2.4%
CVE-2023-36776 HIGH 7.0 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 2.4%
CVE-2021-36372 CRIT 9.8 apache ozone In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to the key. Authenticated users may use them even after access is revoked. 2.4%