57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-28098 | MED 6.4 | apache pulsar The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings. These management operations should be restricted to users with the tenant admin role or super | 1.7% | — |
| CVE-2023-34434 | HIGH 7.5 | apache inlong Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are adv | 1.7% | — |
| CVE-2022-20713 | MED 4.3 | cisco adaptive_security_appliance_software A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an | 1.7% | — |
| CVE-2021-44145 | MED 6.5 | apache nifi In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information. | 1.7% | — |
| CVE-2019-5528 | MED 5.3 | vmware esxi VMware ESXi 6.5 suffers from partial denial of service vulnerability in hostd process. Patch ESXi650-201907201-UG for this issue is available. | 1.7% | — |
| CVE-2011-0806 | MED 5.0 | oracle database_server Unspecified vulnerability in the Network Foundation component in Oracle Database Server 10.1.0.5, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2, when running on Windows, allows remote attackers to affect availability via unknown vectors. | 1.7% | — |
| CVE-2005-0197 | MED 6.1 | cisco ios Cisco IOS 12.1T, 12.2, 12.2T, 12.3 and 12.3T, with Multi Protocol Label Switching (MPLS) installed but disabled, allows remote attackers to cause a denial of service (device reload) via a crafted packet sent to the disabled interface. | 1.7% | — |
| CVE-2025-32897 | CRIT 9.8 | apache seata Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 definition is too narrow. This issue affects Apache Seata (incubatin | 1.7% | — |
| CVE-2022-35278 | MED 6.1 | apache artemis In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue. | 1.7% | — |
| CVE-2022-24485 | HIGH 7.5 | microsoft windows_10 Win32 File Enumeration Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2021-40703 | HIGH 7.8 | adobe premiere_elements Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious m4a file, potentially resulting in arbitrary code execution in the context of the current user. User interaction | 1.7% | — |
| CVE-2021-40702 | HIGH 7.8 | adobe premiere_elements Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious psd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction | 1.7% | — |
| CVE-2021-40701 | HIGH 7.8 | adobe premiere_elements Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious m4a file, potentially resulting in arbitrary code execution in the context of the current user. User interaction | 1.7% | — |
| CVE-2015-6309 | MED 6.8 | cisco email_security_appliance Cisco Email Security Appliance (ESA) 8.5.6-106 and 9.6.0-042 allows remote authenticated users to cause a denial of service (file-descriptor consumption and device reload) via crafted HTTP requests, aka Bug ID CSCuw32211. | 1.7% | — |
| CVE-2024-23952 | MED 6.5 | apache superset This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets. This | 1.7% | — |
| CVE-2023-36021 | HIGH 8.0 | microsoft on-prem_data_gateway Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability | 1.7% | — |
| CVE-2021-40792 | HIGH 7.8 | adobe premiere_pro Adobe Premiere Pro version 15.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to | 1.7% | — |
| CVE-2019-1251 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1244, CVE-2019-1245. | 1.7% | — |
| CVE-2019-1219 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Transaction Manager improperly handles objects in memory, aka 'Windows Transaction Manager Information Disclosure Vulnerability'. | 1.7% | — |
| CVE-2019-1216 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'. | 1.7% | — |
| CVE-2017-6139 | MED 5.9 | f5 big-ip_access_policy_manager In F5 BIG-IP APM software version 13.0.0 and 12.1.2, under rare conditions, the BIG-IP APM system appends log details when responding to client requests. Details in the log file can vary; customers running debug mode logging with BIG-IP APM are at highest risk | 1.7% | — |
| CVE-2026-40357 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.7% | — |
| CVE-2025-21171 | HIGH 7.5 | microsoft .net .NET Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2023-36897 | HIGH 8.1 | microsoft 365_apps Visual Studio Tools for Office Runtime Spoofing Vulnerability | 1.7% | — |
| CVE-2014-3407 | MED 5.0 | cisco adaptive_security_appliance_software The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HTTP packet handling, which allows remote attackers to cause a denial of service (memory consumption) via crafted | 1.7% | — |