57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-0992 | MED 4.2 | microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 2.3% | — |
| CVE-2018-4209 | HIGH 8.8 | apple icloud In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks. | 2.3% | — |
| CVE-2018-4208 | HIGH 8.8 | apple icloud In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks. | 2.3% | — |
| CVE-2022-34722 | CRIT 9.8 | microsoft windows_10 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-40474 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2001-1071 | MED 5.0 | cisco catos Cisco IOS 12.2 and earlier running Cisco Discovery Protocol (CDP) allows remote attackers to cause a denial of service (memory consumption) via a flood of CDP neighbor announcements. | 2.3% | — |
| CVE-2024-38232 | HIGH 7.5 | microsoft windows_10_1607 Windows Networking Denial of Service Vulnerability | 2.3% | — |
| CVE-2024-20670 | HIGH 8.1 | microsoft outlook Outlook for Windows Spoofing Vulnerability | 2.3% | — |
| CVE-2023-44336 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in | 2.3% | — |
| CVE-2022-35824 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2019-8000 | MED 6.5 | adobe photoshop_cc Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound read vulnerability. Successful exploitation could lead to memory leak. | 2.3% | — |
| CVE-2019-7987 | MED 6.5 | adobe photoshop_cc Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound read vulnerability. Successful exploitation could lead to memory leak. | 2.3% | — |
| CVE-2019-7981 | MED 6.5 | adobe photoshop_cc Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound read vulnerability. Successful exploitation could lead to memory leak. | 2.3% | — |
| CVE-2019-7977 | MED 6.5 | adobe photoshop_cc Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound read vulnerability. Successful exploitation could lead to memory leak. | 2.3% | — |
| CVE-2018-18999 | HIGH 7.3 | advantech webaccess\/scada WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user supplied input may allow an attacker to cause the overflow of a buffer on the stack. | 2.3% | — |
| CVE-2015-6406 | MED 4.0 | cisco emergency_responder Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authenticated users to write to arbitrary files via a crafted filename, aka Bug ID CSCuv21781. | 2.3% | — |
| CVE-2014-3323 | MED 4.0 | cisco unified_contact_center_enterprise Directory traversal vulnerability in Cisco Unified Contact Center Enterprise allows remote authenticated users to read arbitrary web-root files via a crafted URL, aka Bug ID CSCun25262. | 2.3% | — |
| CVE-2011-2806 | HIGH 10.0 | google chrome Google Chrome before 13.0.782.215 on Windows does not properly handle vertex data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. | 2.3% | — |
| CVE-2009-2872 | MED 6.8 | cisco ios Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via a malformed packet that is not properly handled during switching from one tunnel t | 2.3% | — |
| CVE-2008-2062 | MED 5.0 | cisco unified_communications_manager The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) before 4.2(3)SR4, and 4.3 before 4.3(2)SR1, allows remote attackers to bypass authentication, and obtain cluster configuration information and statisti | 2.3% | — |
| CVE-2001-0131 | LOW 3.3 | apache http_server htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack. | 2.3% | — |
| CVE-2015-2060 | MED 5.3 | cabextract_project cabextract cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash. | 2.3% | — |
| CVE-2009-4378 | MED 4.3 | wireshark wireshark The IPMI dissector in Wireshark 1.2.0 through 1.2.4 on Windows allows remote attackers to cause a denial of service (crash) via a crafted packet, related to "formatting a date/time using strftime." | 2.3% | — |
| CVE-2024-52338 | CRIT 9.8 | apache arrow Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for | 2.3% | — |
| CVE-2021-26437 | MED 5.5 | microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability | 2.3% | — |