57.020 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
57.020 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-20269 | MED 5.0 | ransomware cisco adaptive_security_appliance_software A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify val | 21.6% | |
| CVE-2014-0312 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014 | 21.6% | — |
| CVE-1999-0886 | HIGH 9.0 | microsoft windows_nt The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager. | 21.6% | — |
| CVE-2014-2776 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE | 21.6% | — |
| CVE-2016-7217 | HIGH 8.8 | microsoft windows_10 Media Foundation in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Media Foundation Memory Corrupti | 21.5% | — |
| CVE-2016-7205 | HIGH 8.8 | microsoft windows_10 Animation Manager in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web | 21.5% | — |
| CVE-2023-36052 | HIGH 8.6 | microsoft azure_command-line_interface Azure CLI REST Command Information Disclosure Vulnerability | 21.5% | — |
| CVE-2013-3863 | HIGH 9.3 | microsoft windows_server_2003 Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via a crafted OLE object in a file, aka "OLE Property Vulnerability." | 21.5% | — |
| CVE-2017-8737 | HIGH 7.5 | microsoft edge Microsoft Windows PDF Library in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way th | 21.5% | — |
| CVE-2017-8728 | HIGH 7.5 | microsoft edge Microsoft Windows PDF Library in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way th | 21.5% | — |
| CVE-1999-0867 | MED 5.0 | microsoft commercial_internet_system Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. | 21.5% | — |
| CVE-2022-43945 | HIGH 7.5 | linux linux_kernel The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining the receive and send buffers of a remote procedure call (RPC) into a single array | 21.5% | — |
| CVE-2006-4219 | HIGH 7.5 | microsoft ie The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN. | 21.5% | — |
| CVE-2010-2266 | MED 5.0 | f5 nginx nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence. | 21.5% | — |
| CVE-2011-1986 | HIGH 9.3 | microsoft excel Use-after-free vulnerability in Microsoft Excel 2003 SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Use after Free WriteAV Vulnerability." | 21.5% | — |
| CVE-2009-1920 | HIGH 9.3 | microsoft windows_2000 The JScript scripting engine 5.1, 5.6, 5.7, and 5.8 in JScript.dll in Microsoft Windows, as used in Internet Explorer, does not properly load decoded scripts into memory before execution, which allows remote attackers to execute arbitrary code via a crafted we | 21.5% | — |
| CVE-2007-2108 | MED 6.8 | microsoft windows Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers to have an unknown impact, aka DB01. NOTE: as of 20070424, Oracle has not disputed reliable claims that this i | 21.5% | — |
| CVE-2010-0025 | MED 5.0 | microsoft exchange_server The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read fragments of e | 21.5% | — |
| CVE-2000-0122 | MED 5.0 | microsoft frontpage Frontpage Server Extensions allows remote attackers to determine the physical path of a virtual directory via a GET request to the htimage.exe CGI program. | 21.5% | — |
| CVE-2017-0243 | HIGH 7.8 | microsoft business_productivity_servers Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8570. | 21.5% | — |
| CVE-2011-0959 | MED 4.3 | cisco unified_operations_manager Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to inject arbitrary web script or HTML via (1) the extn parameter to iptm/advancedfind.do, (2) the deviceInstanceName parameter to | 21.5% | — |
| CVE-2016-3269 | HIGH 8.8 | microsoft edge The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE | 21.4% | — |
| CVE-2008-5745 | MED 4.3 | microsoft windows_media_player Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3) MID file | 21.4% | — |
| CVE-2014-4149 | HIGH 9.3 | microsoft .net_framework Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote attackers to execute arbitrary code via crafted data to a .NET Remoting endpoint, aka "TypeFilterLevel Vulnera | 21.4% | — |
| CVE-2014-4126 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | 21.4% | — |