57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2008-1181 | MED 5.0 | juniper secure_access_2000 Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.cgi without certain parameters, which reveals the path in an "Execute failed" error message. | 2.5% | — |
| CVE-2005-4849 | MED 5.0 | apache derby Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensiti | 2.5% | — |
| CVE-2021-36016 | LOW 3.3 | adobe media_encoder Adobe Media Encoder version 15.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to read arbitrary file system information in the context of t | 2.5% | — |
| CVE-2021-34489 | HIGH 7.8 | microsoft windows_10 DirectWrite Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2009-1168 | HIGH 7.1 | cisco ios Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 through 2.4.0; when RFC4 | 2.5% | — |
| CVE-2022-26901 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-26900 | HIGH 7.8 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 2.4% | — |
| CVE-2024-43521 | HIGH 7.5 | microsoft windows_server_2012 Windows Hyper-V Denial of Service Vulnerability | 2.4% | — |
| CVE-2021-34492 | HIGH 8.1 | microsoft windows_10 Windows Certificate Spoofing Vulnerability | 2.4% | — |
| CVE-2017-7687 | HIGH 7.5 | apache mesos When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev might crash because the code accidentally calls inappropriate function. A malicious act | 2.4% | — |
| CVE-2007-3756 | MED 4.3 | apple safari Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to obtain sensitive information via a crafted web page that identifies the URL of the parent window, even when the parent | 2.4% | — |
| CVE-2021-32567 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. | 2.4% | — |
| CVE-2020-24427 | LOW 3.3 | adobe acrobat Acrobat Reader versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an input validation vulnerability when decoding a crafted codec that could result in the disclosure of sensitive memory. An atta | 2.4% | — |
| CVE-2019-19770 | HIGH 8.2 | linux linux_kernel In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_creat | 2.4% | — |
| CVE-2018-19450 | HIGH 7.8 | foxitsoftware foxit_pdf_sdk_activex A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a launch action. An attacker can leverage this to gain remote code execution. | 2.4% | — |
| CVE-2018-19445 | HIGH 7.8 | foxitsoftware foxit_pdf_sdk_activex A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API app.launchURL is used. An attacker can leverage this to gain remote code execution. | 2.4% | — |
| CVE-2025-21351 | HIGH 7.5 | microsoft windows_10_1607 Windows Active Directory Domain Services API Denial of Service Vulnerability | 2.4% | — |
| CVE-2024-38233 | HIGH 7.5 | microsoft windows_10_1607 Windows Networking Denial of Service Vulnerability | 2.4% | — |
| CVE-2022-28256 | MED 5.5 | adobe acrobat Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to b | 2.4% | — |
| CVE-2021-43899 | CRIT 9.8 | microsoft wireless_display_adapter_firmware Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2015-2062 | HIGH 7.2 | huge-it huge-it_slider Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remote administrators to execute arbitrary SQL commands via the removeslide parameter in a popup_posts or edit_cat action in the sliders_huge_it | 2.4% | — |
| CVE-2017-9790 | HIGH 7.5 | apache mesos When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev crashes if the request path is empty, because the parser assumes the request path always starts with ' | 2.4% | — |
| CVE-2014-2106 | HIGH 7.8 | cisco ios Cisco IOS 15.3M before 15.3(3)M2 and IOS XE 3.10.xS before 3.10.2S allow remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCug45898. | 2.4% | — |
| CVE-2023-36776 | HIGH 7.0 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 2.4% | — |
| CVE-2021-36372 | CRIT 9.8 | apache ozone In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to the key. Authenticated users may use them even after access is revoked. | 2.4% | — |