57.084 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.084 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-3056 | HIGH 10.0 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-9161, CVE-2015- | 12.1% | — |
| CVE-2007-0948 | HIGH 9.3 | microsoft virtual_pc Heap-based buffer overflow in Microsoft Virtual PC 2004 and PC for Mac 7.1 and 7, and Virtual Server 2005 and 2005 R2, allows local guest OS administrators to execute arbitrary code on the host OS via unspecified vectors related to "interaction and initializat | 12.1% | — |
| CVE-2002-1671 | MED 5.0 | microsoft internet_explorer Microsoft Internet Explorer 5.0, 5.01, and 5.5 allows remote attackers to monitor the contents of the clipboard via the getData method of the clipboardData object. | 12.1% | — |
| CVE-2019-7127 | MED 6.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure | 12.1% | — |
| CVE-2019-7110 | MED 6.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure | 12.1% | — |
| CVE-2019-7109 | MED 6.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure | 12.1% | — |
| CVE-2015-6138 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 8 through 11 mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Internet Explorer XSS Filter Bypass Vulnerability." | 12.1% | — |
| CVE-2015-2398 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability." | 12.1% | — |
| CVE-2012-5887 | MED 5.0 | apache tomcat The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for | 12.1% | — |
| CVE-2019-1244 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1245, CVE-2019-1251. | 12.1% | — |
| CVE-2022-20821 | MED 6.5 | cisco ios_xr A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 | 12.1% | |
| CVE-2001-0665 | HIGH 7.5 | microsoft ie Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP | 12.1% | — |
| CVE-2022-29104 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 12.1% | — |
| CVE-2015-0248 | MED 5.0 | apache subversion The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evaluated revis | 12.1% | — |
| CVE-2011-1991 | HIGH 9.3 | microsoft windows_2003_server Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow local users to gain privileges via a Trojan horse DLL in t | 12.1% | — |
| CVE-2018-4918 | CRIT 9.8 | adobe acrobat Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, 2015.006.30394 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the cur | 12.1% | — |
| CVE-2015-1700 | MED 6.0 | microsoft sharepoint_foundation Microsoft SharePoint Server 2007 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, and SharePoint Foundation 2013 SP1 allow remote authenticated users to execute arbitrary code via crafted page content, aka "Microsoft SharePoint Page Content Vul | 12.1% | — |
| CVE-2019-0639 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0680, CVE-2019-0769, CVE-2019-077 | 12.0% | — |
| CVE-2009-1956 | MED 6.4 | apache apr-util Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input. | 12.0% | — |
| CVE-2009-3301 | HIGH 9.3 | apache openoffice Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document. | 12.0% | — |
| CVE-2004-2179 | MED 5.0 | microsoft frontpage asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values. | 12.0% | — |
| CVE-2019-0222 | HIGH 7.5 | apache activemq In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive. | 12.0% | — |
| CVE-2002-0444 | HIGH 7.5 | microsoft windows_2000_terminal_services Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses | 12.0% | — |
| CVE-2023-21715 | HIGH 7.3 | microsoft 365_apps Microsoft Publisher Security Feature Bypass Vulnerability | 12.0% | |
| CVE-1999-0909 | HIGH 7.5 | microsoft terminal_server Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability. | 12.0% | — |