56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.706 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-4211 | CRIT 9.8 | ibm spectrum_protect IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force I | 71.1% | — |
| CVE-2015-2509 | HIGH 9.3 | microsoft windows_7 Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Media Center link (mcl) file, aka "Windows Media Center RCE Vulnerability." | 71.0% | — |
| CVE-2019-0887 | HIGH 8.0 | microsoft remote_desktop_client A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'. | 71.0% | — |
| CVE-2015-0096 | HIGH 9.3 | microsoft windows_7 Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain priv | 71.0% | — |
| CVE-2024-49112 | CRIT 9.8 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 70.9% | — |
| CVE-2017-12616 | HIGH 7.5 | apache tomcat When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request. | 70.8% | — |
| CVE-2014-1762 | HIGH 7.5 | microsoft internet_explorer Unspecified vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code with medium-integrity privileges and bypass a sandbox protection mechanism via unknown vectors, as demonstrated by ZDI during a Pwn4Fun comp | 70.7% | — |
| CVE-2024-20353 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting i | 70.7% | |
| CVE-2013-3163 | HIGH 8.8 | microsoft internet_explorer Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013 | 70.7% | |
| CVE-2025-20333 | CRIT 9.9 | cisco adaptive_security_appliance_software A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. | 70.7% | |
| CVE-2020-17143 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability | 70.6% | — |
| CVE-2023-43622 | HIGH 7.5 | apache http_server An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known "slow loris" at | 70.6% | — |
| CVE-2024-38063 | CRIT 9.8 | microsoft windows_10_1507 Windows TCP/IP Remote Code Execution Vulnerability | 70.6% | — |
| CVE-2017-6736 | HIGH 8.8 | cisco ios The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. | 70.6% | |
| CVE-2007-6750 | MED 5.0 | apache http_server The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15. | 70.5% | — |
| CVE-2001-1243 | MED 5.0 | microsoft internet_information_server Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) rem | 70.5% | — |
| CVE-2019-0199 | HIGH 7.5 | apache tomcat The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open | 70.5% | — |
| CVE-1999-0513 | MED 5.0 | digital unix ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service. | 70.5% | — |
| CVE-2015-0336 | HIGH 9.3 | adobe flash_player Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015- | 70.4% | — |
| CVE-2023-20864 | CRIT 9.8 | vmware aria_operations_for_logs VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root. | 70.4% | — |
| CVE-2012-1535 | HIGH 7.8 | adobe flash_player Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted SWF content, as exploite | 70.4% | |
| CVE-2020-13951 | HIGH 7.5 | apache openmeetings Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. | 70.4% | — |
| CVE-2016-7288 | HIGH 7.5 | microsoft edge The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-72 | 70.4% | — |
| CVE-2022-23270 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 70.3% | — |
| CVE-2005-0045 | HIGH 7.5 | microsoft windows_2000 The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 com | 70.3% | — |