57.075 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.075 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-0941 | MED 5.5 | microsoft exchange_server Microsoft Exchange Server 2016 Cumulative Update 7 and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how data is imported, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is uniq | 12.5% | — |
| CVE-2002-1592 | MED 5.0 | apache http_server The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information. | 12.5% | — |
| CVE-1999-0489 | HIGH 10.0 | microsoft windows_nt MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013. | 12.4% | — |
| CVE-2019-1072 | CRIT 9.8 | microsoft azure_devops_server A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'. | 12.4% | — |
| CVE-2015-2402 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability." | 12.4% | — |
| CVE-2010-0437 | HIGH 7.8 | linux linux_kernel The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of serv | 12.4% | — |
| CVE-2005-4844 | HIGH 7.1 | microsoft internet_explorer The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer. | 12.4% | — |
| CVE-2025-27480 | HIGH 8.1 | microsoft windows_server_2012 Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 12.4% | — |
| CVE-2002-0101 | MED 5.0 | microsoft internet_explorer Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released. | 12.4% | — |
| CVE-2022-27511 | HIGH 8.1 | citrix application_delivery_management Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the d | 12.4% | — |
| CVE-2022-20624 | HIGH 8.6 | cisco nx-os A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validati | 12.4% | — |
| CVE-2014-8967 | MED 6.8 | microsoft internet_explorer Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted HTML document in conjunction with a Cascading Style Sheets (CSS) token sequence specifying the run-in value for the display property, le | 12.4% | — |
| CVE-2018-16844 | HIGH 7.5 | apple xcode nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' di | 12.4% | — |
| CVE-2019-0594 | HIGH 8.8 | microsoft sharepoint_enterprise_server A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0604. | 12.4% | — |
| CVE-2009-1191 | MED 5.0 | apache http_server mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request. | 12.4% | — |
| CVE-2024-43491 | CRIT 9.8 | microsoft windows_10_1507 Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these pre | 12.4% | — |
| CVE-2020-1457 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1425. | 12.4% | — |
| CVE-2001-0153 | HIGH 7.5 | microsoft visual_basic Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands. | 12.4% | — |
| CVE-2021-35516 | HIGH 7.5 | apache commons_compress When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Comp | 12.4% | — |
| CVE-2022-22978 | CRIT 9.8 | netapp active_iq_unified_manager In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression a | 12.4% | — |
| CVE-2015-7705 | CRIT 9.8 | citrix xenserver The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests. | 12.4% | — |
| CVE-2024-38206 | HIGH 8.5 | microsoft copilot_studio An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network. | 12.3% | — |
| CVE-2005-0360 | MED 5.0 | microsoft log_sink_class_activex_control The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files. | 12.3% | — |
| CVE-2011-1652 | MED 5.0 | microsoft windows_7 The default configuration of Microsoft Windows 7 immediately prefers a new IPv6 and DHCPv6 service over a currently used IPv4 and DHCPv4 service upon receipt of an IPv6 Router Advertisement (RA), and does not provide an option to ignore an unexpected RA, which | 12.3% | — |
| CVE-2019-0758 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0882, CVE-2019-0961. | 12.3% | — |