57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2002-1933 | HIGH 7.2 | microsoft windows_2000_terminal_services The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window. | 1.6% | — |
| CVE-2022-38048 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2021-42526 | HIGH 7.8 | adobe premiere_elements Adobe Premiere Elements 20210809.daily.2242976 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction i | 1.6% | — |
| CVE-2022-24526 | MED 6.1 | microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability | 1.6% | — |
| CVE-2022-24512 | MED 6.3 | fedoraproject fedora .NET and Visual Studio Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2021-40460 | MED 6.5 | microsoft windows_10 Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability | 1.6% | — |
| CVE-2020-1170 | HIGH 7.8 | microsoft forefront_endpoint_protection_2010 An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulne | 1.6% | — |
| CVE-2018-4271 | MED 6.5 | apple icloud Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6. | 1.6% | — |
| CVE-2023-52291 | MED 4.7 | apache streampark In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to | 1.6% | — |
| CVE-2017-12278 | MED 6.3 | cisco wireless_lan_controller_software A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Wireless LAN Controllers could allow an authenticated, remote attacker to cause an affected device to restart, resulting in a denial of service (DoS) condition. The vulnerabili | 1.6% | — |
| CVE-2017-6757 | HIGH 8.8 | cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager 10.5(2.10000.5), 11.0(1.10000.10), and 11.5(1.10000.6) could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-supplie | 1.6% | — |
| CVE-2011-1192 | MED 5.0 | google chrome Google Chrome before 10.0.648.127 on Linux does not properly handle Unicode ranges, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | 1.6% | — |
| CVE-2004-0747 | HIGH 7.8 | apache http_server Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables. | 1.6% | — |
| CVE-2020-7880 | HIGH 7.5 | douzone neors The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because of improper parameter validation of StartNeoRS function in ActiveX. | 1.6% | — |
| CVE-2021-38650 | HIGH 7.6 | microsoft 365_apps Microsoft Office Spoofing Vulnerability | 1.6% | — |
| CVE-2016-8479 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comprom | 1.6% | — |
| CVE-2016-6761 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to eleva | 1.6% | — |
| CVE-2016-6760 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to eleva | 1.6% | — |
| CVE-2016-6759 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to eleva | 1.6% | — |
| CVE-2016-6758 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to eleva | 1.6% | — |
| CVE-2012-4099 | MED 4.3 | cisco nx-os The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service reset and resync) via a malformed UPDATE message, aka Bug ID CSCtn13065. | 1.6% | — |
| CVE-2012-0179 | HIGH 7.2 | microsoft windows_7 Double free vulnerability in tcpip.sys in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that binds an IPv6 address to a local interface, aka "TCP/IP Double Free Vulnerabil | 1.6% | — |
| CVE-2010-3889 | HIGH 7.2 | microsoft windows Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers. | 1.6% | — |
| CVE-2007-2587 | MED 6.3 | cisco ios The IOS FTP Server in Cisco IOS 11.3 through 12.4 allows remote authenticated users to cause a denial of service (IOS reload) via unspecified vectors involving transferring files (aka bug ID CSCse29244). | 1.6% | — |
| CVE-2003-0350 | MED 4.6 | microsoft windows_2000 The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager tha | 1.6% | — |