57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-8440 | CRIT 9.8 | linux linux_kernel Possible buffer overflow in SMMU system call. Improper input validation in ADSP SID2CB system call may result in hypervisor memory overwrite. Product: Android. Versions: Kernel 3.18. Android ID: A-31625306. References: QC-CR#1036747. | 2.2% | — |
| CVE-2024-28915 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2024-28911 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2023-35077 | HIGH 7.5 | ivanti endpoint_manager An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product version 7.9.1.285 or above. | 2.2% | — |
| CVE-2022-26785 | MED 6.5 | microsoft windows_server_2016 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability | 2.2% | — |
| CVE-2017-3150 | MED 6.1 | apache atlas Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script. | 2.2% | — |
| CVE-2025-21299 | HIGH 7.1 | microsoft windows_10_1507 Windows Kerberos Security Feature Bypass Vulnerability | 2.2% | — |
| CVE-2021-42316 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2023-38238 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such a | 2.2% | — |
| CVE-2022-22394 | HIGH 8.8 | ibm spectrum_protect The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access controls. By signing in, an attacker could exploit this vulnerability to bypass security and gain unauthorized ad | 2.2% | — |
| CVE-2021-36066 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 21.2.10 (and earlier) and 22.4.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 2.2% | — |
| CVE-2018-0049 | HIGH 7.5 | juniper junos A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to cause the Junos OS kernel to crash. Continued receipt of this specifically crafted malicious MPLS packet will cause a sustained Denial of Service condition. This issue | 2.2% | — |
| CVE-2015-6310 | MED 5.0 | cisco unified_communications_manager_im_and_presence_service The REST interface in Cisco Unified Communications Manager IM and Presence Service 11.5(1) allows remote attackers to cause a denial of service (SIP proxy service restart) via a crafted HTTP request, aka Bug ID CSCuw31632. | 2.2% | — |
| CVE-2015-6288 | MED 5.0 | cisco content_security_management_appliance Cisco Content Security Management Appliance (SMA) 7.8.0-000 does not properly validate credentials, which allows remote attackers to cause a denial of service (rapid log-file rollover and application fault) via crafted HTTP requests, aka Bug ID CSCuw09620. | 2.2% | — |
| CVE-2024-45505 | HIGH 8.8 | apache hertzbeat Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6. | 2.2% | — |
| CVE-2017-15713 | MED 6.5 | apache hadoop Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct | 2.2% | — |
| CVE-2016-3306 | HIGH 7.8 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 mishandles session objects, which allows local users to hijack sessi | 2.2% | — |
| CVE-2012-2488 | HIGH 7.8 | cisco asr_9000_rsp440_router Cisco IOS XR before 4.2.1 on ASR 9000 series devices and CRS series devices allows remote attackers to cause a denial of service (packet transmission outage) via a crafted packet, aka Bug IDs CSCty94537 and CSCtz62593. | 2.2% | — |
| CVE-2022-30173 | HIGH 7.8 | microsoft excel Microsoft Excel Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-43889 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-40453 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2020-36158 | HIGH 8.8 | debian debian_linux mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332. | 2.2% | — |
| CVE-2025-21308 | MED 6.5 | microsoft windows_10_1507 Windows Themes Spoofing Vulnerability | 2.2% | — |
| CVE-2023-35377 | MED 6.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.2% | — |
| CVE-2023-35376 | MED 6.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.2% | — |