57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-41782 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled. | 2.0% | — |
| CVE-2021-41781 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled. | 2.0% | — |
| CVE-2022-22970 | MED 5.3 | netapp active_iq_unified_manager In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. | 2.0% | — |
| CVE-2019-8064 | MED 4.3 | adobe acrobat_dc Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to i | 2.0% | — |
| CVE-2017-3846 | HIGH 8.6 | cisco tidal_enterprise_scheduler A vulnerability in the Client Manager Server of Cisco Workload Automation and Cisco Tidal Enterprise Scheduler could allow an unauthenticated, remote attacker to retrieve any file from the Client Manager Server. The vulnerability is due to insufficient input v | 2.0% | — |
| CVE-2014-1814 | HIGH 7.2 | microsoft windows_7 The Windows Installer in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a c | 2.0% | — |
| CVE-2013-2779 | HIGH 7.8 | cisco asr_1001 Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of ser | 2.0% | — |
| CVE-2012-0725 | HIGH 9.3 | adobe air Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2012-0724. | 2.0% | — |
| CVE-2012-0724 | HIGH 9.3 | adobe air Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2012-0725. | 2.0% | — |
| CVE-2000-0663 | MED 4.6 | microsoft windows_2000 The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, | 2.0% | — |
| CVE-2025-21330 | HIGH 7.5 | microsoft windows_10_1809 Windows Remote Desktop Services Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-35338 | HIGH 7.5 | microsoft windows_10_1507 Windows Peer Name Resolution Protocol Denial of Service Vulnerability | 2.0% | — |
| CVE-2019-16647 | HIGH 7.2 | maxthon maxthon_browser Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows. | 2.0% | — |
| CVE-2016-8742 | HIGH 7.8 | apache couchdb The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the ns | 2.0% | — |
| CVE-2017-12225 | MED 6.5 | cisco prime_lan_management_solution A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack another user's administrative session, aka a Session Fixation Vulnerability. The vulnerability is due to the reuse of a | 2.0% | — |
| CVE-2025-23317 | CRIT 9.1 | nvidia triton_inference_server NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP request. A successful exploit of this vulnerability might lead to remote code execution, denial of ser | 2.0% | — |
| CVE-2021-24109 | MED 6.8 | microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2021-1302 | HIGH 8.8 | cisco catalyst_sd-wan_manager Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and | 2.0% | — |
| CVE-2019-14207 | HIGH 7.5 | foxitsoftware phantompdf An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling the clone function due to an endless loop resulting from confusing relationships between a child and parent object (caused by an append error). | 2.0% | — |
| CVE-2018-1845 | HIGH 7.1 | ibm infosphere_governance_catalog IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X | 2.0% | — |
| CVE-2013-5473 | HIGH 7.8 | cisco ios Memory leak in Cisco IOS 12.2, 15.1, and 15.2; IOS XE 3.4.2S through 3.4.5S; and IOS XE 3.6.xS before 3.6.1S allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed IKEv1 packets, aka Bug ID CSCtx66011. | 2.0% | — |
| CVE-2013-1167 | HIGH 7.1 | cisco asr_1001 Cisco IOS XE 3.2 through 3.4 before 3.4.2S, and 3.5, on 1000 series Aggregation Services Routers (ASR), when bridge domain interface (BDI) is enabled, allows remote attackers to cause a denial of service (card reload) via packets that are not properly handled | 2.0% | — |
| CVE-2010-1887 | MED 4.4 | microsoft windows_2003_server The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, which allo | 2.0% | — |
| CVE-2023-29363 | CRIT 9.8 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-39832 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by a memory corruption vulnerability due to insecure handling of a malicious PDF file, potentially resulting in arbitrary code execution in the context o | 2.0% | — |