57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-37977 | MED 6.5 | microsoft windows_10 Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | 1.9% | — |
| CVE-2022-24494 | HIGH 7.8 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2022-23197 | MED 5.5 | adobe illustrator Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex | 1.9% | — |
| CVE-2022-23196 | MED 5.5 | adobe illustrator Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex | 1.9% | — |
| CVE-2022-23195 | MED 5.5 | adobe illustrator Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex | 1.9% | — |
| CVE-2022-23194 | MED 5.5 | adobe illustrator Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex | 1.9% | — |
| CVE-2022-23191 | MED 5.5 | adobe illustrator Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex | 1.9% | — |
| CVE-2022-23190 | MED 5.5 | adobe illustrator Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex | 1.9% | — |
| CVE-2017-7034 | HIGH 8.8 | apple icloud An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the | 1.9% | — |
| CVE-2017-7030 | HIGH 8.8 | apple icloud An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the | 1.9% | — |
| CVE-2008-5548 | HIGH 9.3 | virusbuster virusbuster VirusBuster 4.5.11.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt e | 1.9% | — |
| CVE-2008-5546 | HIGH 9.3 | virusblokada vba32_antivirus VirusBlokAda VBA32 3.12.8.5, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a | 1.9% | — |
| CVE-2008-5544 | HIGH 9.3 | hacksoft the_hacker Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to | 1.9% | — |
| CVE-2008-5530 | HIGH 9.3 | avg ewido_security_suite Ewido Security Suite 4.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .t | 1.9% | — |
| CVE-2008-5521 | HIGH 9.3 | free-av antivir Avira AntiVir 7.9.0.36 and possibly 7.8.1.28, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no | 1.9% | — |
| CVE-2008-5520 | HIGH 9.3 | ahnlab v3_internet_security AhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) | 1.9% | — |
| CVE-2025-49683 | HIGH 7.8 | microsoft windows_10_1507 Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally. | 1.9% | — |
| CVE-2023-35391 | MED 6.2 | microsoft .net ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability | 1.9% | — |
| CVE-2019-1900 | HIGH 7.5 | cisco integrated_management_controller_supervisor A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to cause the web server process to crash, causing a denial of service (DoS) condition on an affected system. The vulnerability is | 1.9% | — |
| CVE-2018-11786 | HIGH 8.8 | apache karaf In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with rights to the Karaf console can pivot and read/write any file on the file system to which the Karaf process user | 1.9% | — |
| CVE-2013-5553 | HIGH 7.8 | cisco ios Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of service (memory consumption or device reload) by sending a crafted SIP message over (1) IPv4 or (2) IPv6, aka Bug IDs CSCuc42558 and CSCug25383. | 1.9% | — |
| CVE-2013-3388 | HIGH 7.8 | cisco prime_central_for_hosted_collaboration_solution_assurance Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets to port 44444, aka Bug ID CSCtz92776. | 1.9% | — |
| CVE-2013-3382 | HIGH 7.8 | cisco adaptive_security_appliance The Next-Generation Firewall (aka NGFW, formerly CX Context-Aware Security) module 9.x before 9.1.1.9 and 9.1.2.x before 9.1.2.12 for Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (device reload or traffi | 1.9% | — |
| CVE-2008-0527 | HIGH 7.8 | cisco session_initiation_protocol_\(sip\)_firmware The HTTP server in Cisco Unified IP Phone 7935 and 7936 running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a crafted HTTP request. | 1.9% | — |
| CVE-2023-36542 | HIGH 8.8 | apache nifi Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution in | 1.9% | — |