57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-25691 | CRIT 9.8 | apache apache-airflow-providers-google Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0. | 1.6% | — |
| CVE-2019-14215 | HIGH 7.5 | foxitsoftware phantompdf An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling xfa.event.rest XFA JavaScript due to accessing a wild pointer. | 1.6% | — |
| CVE-2019-14214 | HIGH 7.5 | foxitsoftware phantompdf An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a JavaScript Denial of Service when deleting pages in a document that contains only one page by calling a "t.hidden = true" function. | 1.6% | — |
| CVE-2019-14210 | HIGH 7.5 | foxitsoftware phantompdf An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to Memory Corruption due to the use of an invalid pointer copy, resulting from a destructed string object. | 1.6% | — |
| CVE-2019-13067 | CRIT 9.8 | f5 njs njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place. | 1.6% | — |
| CVE-2026-9155 | HIGH 8.8 | gnu sed OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input validation. | 1.6% | — |
| CVE-2026-21536 | CRIT 9.8 | microsoft devices_pricing_program Microsoft Devices Pricing Program Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2025-21364 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability | 1.6% | — |
| CVE-2021-28315 | HIGH 7.8 | microsoft windows_10 Windows Media Video Decoder Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2020-1160 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. | 1.6% | — |
| CVE-2020-3168 | HIGH 7.5 | cisco nx-os A vulnerability in the Secure Login Enhancements capability of Cisco Nexus 1000V Switch for VMware vSphere could allow an unauthenticated, remote attacker to cause an affected Nexus 1000V Virtual Supervisor Module (VSM) to become inaccessible to users through | 1.6% | — |
| CVE-2014-1715 | HIGH 7.5 | google chrome Directory traversal vulnerability in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows has unspecified impact and attack vectors. | 1.6% | — |
| CVE-2014-0674 | MED 6.8 | cisco video_surveillance_operations_manager Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to obtain sensitive information, modify data, or cause a denial of service by leveraging network connectivity from | 1.6% | — |
| CVE-2025-62213 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 1.6% | — |
| CVE-2024-43469 | HIGH 8.8 | microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-38114 | HIGH 8.8 | microsoft windows_10_1507 Windows IP Routing Management Snapin Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2023-21761 | HIGH 7.5 | microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability | 1.6% | — |
| CVE-2013-1225 | HIGH 7.8 | cisco unified_customer_voice_portal Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entity declaration in conjunction with an entity reference, relate | 1.6% | — |
| CVE-2004-0186 | HIGH 7.2 | linux linux_kernel smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted. | 1.6% | — |
| CVE-2022-37866 | HIGH 7.5 | apache ivy When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include placeholders for artifacts coordinates like the organisation, module or version. If said coordinates contain "../" | 1.6% | — |
| CVE-2022-26183 | HIGH 8.8 | pnpm pnpm PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is | 1.6% | — |
| CVE-2020-16864 | MED 5.4 | microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially | 1.6% | — |
| CVE-2020-16861 | MED 5.4 | microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially | 1.6% | — |
| CVE-2020-5408 | MED 6.5 | pivotal_software spring_security Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious | 1.6% | — |
| CVE-2018-0051 | HIGH 7.5 | juniper junos A Denial of Service vulnerability in the SIP application layer gateway (ALG) component of Junos OS based platforms allows an attacker to crash MS-PIC, MS-MIC, MS-MPC, MS-DPC or SRX flow daemon (flowd) process. This issue affects Junos OS devices with NAT or st | 1.6% | — |