IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2005-0177 HIGH 7.8 linux linux_kernel nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow. 2.4%
CVE-2026-40398 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. 2.4%
CVE-2024-38015 HIGH 7.5 microsoft windows_server_2012 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability 2.4%
CVE-2021-43882 CRIT 9.0 microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability 2.4%
CVE-2021-28618 MED 5.5 adobe animate Adobe Animate version 21.0.6 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the cu 2.4%
CVE-2021-28617 MED 5.5 adobe animate Adobe Animate version 21.0.6 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the cu 2.4%
CVE-2016-6357 HIGH 7.5 cisco email_security_appliance A vulnerability in the configured security policies, including drop email filtering, in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass a configured drop filter by using an email with a corrupted 2.4%
CVE-2016-1480 HIGH 7.5 cisco email_security_appliance A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters 2.4%
CVE-2026-26169 MED 6.1 microsoft windows_10_1607 Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally. 2.4%
CVE-2021-28570 HIGH 8.3 adobe after_effects Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could exploit this to to plant custom binaries and execute them with System permissions. Exploitation of this issue req 2.4%
CVE-2016-4728 HIGH 8.8 apple iphone_os WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 mishandles error prototypes, which allows remote attackers to execute arbitrary code via a crafted web site. 2.4%
CVE-2004-1649 HIGH 7.2 microsoft windows_2000 Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter. NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future. 2.4%
CVE-2022-24543 HIGH 7.8 microsoft windows_upgrade_assistant Windows Upgrade Assistant Remote Code Execution Vulnerability 2.4%
CVE-2021-39860 MED 5.5 adobe acrobat Acrobat Pro DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive us 2.4%
CVE-2021-3178 MED 6.5 debian debian_linux fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export 2.4%
CVE-2020-16939 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit the vulnerability, an attacker would first hav 2.4%
CVE-2016-5308 MED 5.5 symantec client_intrusion_detection_system The Client Intrusion Detection System (CIDS) driver before 15.0.6 in Symantec Endpoint Protection (SEP) and before 15.1.2 in Norton Security allows remote attackers to cause a denial of service (memory corruption and system crash) via a malformed Portable Exec 2.4%
CVE-2022-24520 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability 2.4%
CVE-2022-24517 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability 2.4%
CVE-2022-24471 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability 2.4%
CVE-2022-24470 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability 2.4%
CVE-2022-24468 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability 2.4%
CVE-2022-24467 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability 2.4%
CVE-2019-7401 CRIT 9.8 f5 nginx_unit NGINX Unit before 1.7.1 might allow an attacker to cause a heap-based buffer overflow in the router process with a specially crafted request. This may result in a denial of service (router process crash) or possibly have unspecified other impact. 2.4%
CVE-2018-0904 MED 4.7 microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows information disclosure vulne 2.4%