57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-0600 | MED 5.0 | cisco unified_ip_phones_9900_series_firmware The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to cause a denial of service (logoff) via crafted packets, aka Bug ID CSCuq12139. | 2.2% | — |
| CVE-2014-3345 | MED 5.0 | cisco transport_gateway_installation_software The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check authorization for administrative web pages, which allows remote attackers to modify the product via a crafted U | 2.2% | — |
| CVE-2022-28845 | HIGH 7.8 | adobe bridge Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 2.2% | — |
| CVE-2022-28844 | HIGH 7.8 | adobe bridge Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 2.2% | — |
| CVE-2022-28843 | HIGH 7.8 | adobe bridge Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 2.2% | — |
| CVE-2022-28839 | HIGH 7.8 | adobe bridge Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 2.2% | — |
| CVE-2020-23922 | HIGH 7.1 | apache bookkeeper An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read. | 2.2% | — |
| CVE-2014-2109 | HIGH 7.8 | cisco ios The TCP Input module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted TCP packets, aka Bug IDs CSCuh33843 and CSCuj41494. | 2.2% | — |
| CVE-2008-0029 | HIGH 10.0 | cisco application_velocity_system Cisco Application Velocity System (AVS) before 5.1.0 is installed with default passwords for some system accounts, which allows remote attackers to gain privileges. | 2.2% | — |
| CVE-2005-3059 | HIGH 10.0 | opera opera_browser Multiple unspecified vulnerabilities in Opera 8.50 on Linux and Windows have unknown impact and attack vectors, related to (1) " handling of must-revalidate cache directive for HTTPS pages" or (2) a "display issue with cookie comment encoding." | 2.2% | — |
| CVE-2022-35772 | HIGH 7.2 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-43233 | HIGH 7.5 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2019-1704 | HIGH 7.5 | cisco secure_firewall_threat_defense Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent or remote attacker to cause a denial of service (DoS) condition. For mo | 2.2% | — |
| CVE-2009-3885 | MED 5.0 | sun jre Sun Java SE 5.0 before Update 22 and 6 before Update 17 on Windows allows remote attackers to cause a denial of service via a BMP file containing a link to a UNC share pathname for an International Color Consortium (ICC) profile file, probably a related issue | 2.2% | — |
| CVE-2006-6588 | HIGH 7.5 | apache ofbiz The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of conten | 2.2% | — |
| CVE-2026-64881 | HIGH 8.8 | tenable security_center The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability. | 2.2% | — |
| CVE-2025-26647 | HIGH 8.8 | microsoft windows_server_2008 Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network. | 2.2% | — |
| CVE-2021-34525 | HIGH 8.8 | microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-34508 | HIGH 8.8 | microsoft windows_10 Windows Kernel Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2017-2340 | MED 5.3 | juniper junos On Juniper Networks Junos OS 15.1 releases from 15.1R3 to 15.1R4, 16.1 prior to 16.1R3, on M/MX platforms where Enhanced Subscriber Management for DHCPv6 subscribers is configured, a vulnerability in processing IPv6 ND packets originating from subscribers and | 2.2% | — |
| CVE-2016-1359 | HIGH 8.8 | cisco prime_infrastructure Cisco Prime Infrastructure 3.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP request that is mishandled during viewing of a log file, aka Bug ID CSCuw81494. | 2.2% | — |
| CVE-2019-0993 | MED 4.2 | microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 2.2% | — |
| CVE-2019-0991 | MED 4.2 | microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 2.2% | — |
| CVE-2017-15942 | HIGH 7.5 | paloaltonetworks pan-os Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.13, and 8.0.x before 8.0.6 allows remote attackers to cause a denial of service via vectors related to the management interface. | 2.2% | — |
| CVE-2024-21643 | HIGH 7.1 | microsoft identitymodel_extensions IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol or the `SignedHttpRequestValidator`is vulnerable. Mi | 2.2% | — |