57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-37326 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37323 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37322 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37319 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-28928 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-21449 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-21425 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-21331 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-21317 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-20701 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2011-0219 | MED 5.8 | apple safari Apple Safari before 5.0.6 allows remote attackers to bypass the Same Origin Policy, and modify the rendering of text from arbitrary web sites, via a Java applet that loads fonts. | 1.6% | — |
| CVE-2025-21295 | HIGH 8.1 | microsoft windows_10_1507 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2023-41834 | MED 6.1 | apache flink_stateful_functions Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted HTTP requests. Attackers could | 1.6% | — |
| CVE-2020-7821 | HIGH 7.8 | nexaweb nexacro_14 Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by modifying the value of registry path. This can be leveraged for code execution by rebooting the victim’s PC | 1.6% | — |
| CVE-2020-7820 | HIGH 7.8 | nexaweb nexacro_14 Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by setting the arguments to the vulnerable API. This can be leveraged for code execution by rebooting the victim’s PC | 1.6% | — |
| CVE-2019-19169 | HIGH 7.8 | raonwiz dext5 Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution. | 1.6% | — |
| CVE-2019-19168 | HIGH 7.8 | raonwiz dext5 Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution. | 1.6% | — |
| CVE-2022-31702 | CRIT 9.8 | vmware vrealize_network_insight vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication. | 1.6% | — |
| CVE-2022-38040 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-38031 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-37982 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2020-24431 | MED 4.4 | adobe acrobat Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a security feature bypass that could result in dynamic library code injection by the Adobe Reader process. Exploita | 1.6% | — |
| CVE-2020-1576 | HIGH 8.5 | microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP | 1.6% | — |
| CVE-2014-4024 | MED 5.9 | f5 big-ip_access_policy_manager SSL virtual servers in F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 before HF8, 11.4.1 before HF5, 11.5.0 before HF5, and 11.5.1 before HF5, when used with third-party Secure Sockets Layer (SSL) accelerator card | 1.6% | — |
| CVE-2017-12631 | HIGH 8.8 | apache cxf_fediz Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3 and Spring 4 plugins in versions before 1.4.3 and 1.3 | 1.6% | — |