57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-26183 | MED 6.5 | microsoft windows_10_1507 Windows Kerberos Denial of Service Vulnerability | 2.2% | — |
| CVE-2020-3791 | MED 4.3 | adobe photoshop_2020 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.2% | — |
| CVE-2020-3782 | MED 4.3 | adobe photoshop_2020 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.2% | — |
| CVE-2020-3781 | MED 4.3 | adobe photoshop_2020 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.2% | — |
| CVE-2020-3778 | MED 4.3 | adobe photoshop_2020 Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.2% | — |
| CVE-2020-3771 | MED 4.3 | adobe photoshop_2020 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.2% | — |
| CVE-2019-1363 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'. | 2.2% | — |
| CVE-2019-8037 | MED 4.3 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful ex | 2.2% | — |
| CVE-2016-10318 | MED 6.5 | linux linux_kernel A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel before 4.7.4 allows a user to assign an encryption policy to a directory owned by a different user | 2.2% | — |
| CVE-2000-0933 | MED 4.6 | microsoft windows_2000 The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recogniti | 2.2% | — |
| CVE-2019-1463 | MED 5.5 | microsoft office An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1400. | 2.2% | — |
| CVE-2019-1400 | MED 5.5 | microsoft office An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1463. | 2.2% | — |
| CVE-2009-1758 | MED 5.0 | xen xen The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest OS by triggering a segmentatio | 2.2% | — |
| CVE-2003-0258 | HIGH 7.5 | cisco vpn_3000_concentrator_series_software Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication. | 2.2% | — |
| CVE-2021-34474 | HIGH 8.0 | microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2015-0624 | MED 4.3 | cisco content_security_management_appliance The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur444 | 2.2% | — |
| CVE-2022-28199 | MED 6.5 | nvidia data_plane_development_kit NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and | 2.2% | — |
| CVE-2020-3315 | MED 5.3 | cisco ios Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors in how the Snort detecti | 2.2% | — |
| CVE-2018-0333 | MED 5.8 | cisco secure_firewall_management_center A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass | 2.2% | — |
| CVE-2016-7913 | HIGH 7.8 | canonical ubuntu_linux The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) via vectors involving omission of the firmware name from a certain data str | 2.2% | — |
| CVE-2024-38072 | HIGH 7.5 | microsoft windows_server_2016 Windows Remote Desktop Licensing Service Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-38041 | MED 5.5 | microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability | 2.2% | — |
| CVE-2024-20345 | MED 6.5 | cisco appdynamics_controller A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. This vulnerability is due to insufficient validation of user-suppli | 2.2% | — |
| CVE-2023-29328 | HIGH 8.8 | microsoft teams Microsoft Teams Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2002-0853 | MED 5.0 | cisco vpn_client Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a packet with a zero-length payload. | 2.2% | — |