57.435 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.435 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2009-1557 | MED 4.3 | cisco wvc54gca Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allow remote attackers to inject arbitrary web script or HTML via the next_file parameter to (1) main.cgi, (2) img/main.cg | 7.5% | — |
| CVE-2019-1390 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. | 7.5% | — |
| CVE-2011-1984 | HIGH 7.2 | microsoft windows_2003_server WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability." | 7.5% | — |
| CVE-2017-0220 | MED 4.7 | microsoft windows_7 The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a | 7.5% | — |
| CVE-2014-3673 | HIGH 7.5 | canonical ubuntu_linux The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c. | 7.5% | — |
| CVE-2012-4534 | LOW 2.6 | apache tomcat org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the | 7.5% | — |
| CVE-2000-0331 | MED 5.0 | microsoft terminal_server Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability. | 7.5% | — |
| CVE-2017-3122 | MED 6.5 | adobe acrobat Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) da | 7.4% | — |
| CVE-2025-53786 | HIGH 8.0 | microsoft exchange_server On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following furt | 7.4% | — |
| CVE-2007-4223 | HIGH 10.0 | microsoft sysinternals_debugview Dbgv.sys in Microsoft Sysinternals DebugView before 4.72 provides an unspecified mechanism for copying data into kernel memory, which allows local users to gain privileges via unspecified vectors. | 7.4% | — |
| CVE-2019-12401 | HIGH 7.5 | apache solr Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will exp | 7.4% | — |
| CVE-2016-1429 | HIGH 7.5 | cisco rv180_vpn_router_firmware Directory traversal vulnerability in the web interface on Cisco RV180 and RV180W devices allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuz43023. | 7.4% | — |
| CVE-1999-1473 | MED 5.0 | microsoft internet_explorer When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue." | 7.4% | — |
| CVE-2018-15978 | HIGH 7.5 | adobe flash_player Flash Player versions 31.0.0.122 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 7.4% | — |
| CVE-2005-3483 | HIGH 7.5 | graphon go-global Buffer overflow in GO-Global for Windows 3.1.0.3270 and earlier allows remote attackers to execute arbitrary code via a data block that is longer than the specified data block size. | 7.4% | — |
| CVE-2015-1836 | HIGH 7.3 | apache hbase Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a d | 7.4% | — |
| CVE-2008-2476 | HIGH 9.3 | force10 ftos The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neigh | 7.4% | — |
| CVE-2002-0240 | MED 5.0 | apache http_server PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message. | 7.4% | — |
| CVE-2025-32711 | CRIT 9.3 | microsoft 365_copilot Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 7.4% | — |
| CVE-2021-36936 | HIGH 8.8 | microsoft windows_10 Windows Print Spooler Remote Code Execution Vulnerability | 7.4% | — |
| CVE-2017-2970 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the XSLT engine related to template manipulation. Successful exploitation could lead to arbitrary code exec | 7.4% | — |
| CVE-2021-21051 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 21.2.4 (and earlier) and 22.1.1 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted javascript file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code exe | 7.4% | — |
| CVE-2021-44705 | HIGH 7.8 | adobe acrobat Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the contex | 7.4% | — |
| CVE-2021-22921 | HIGH 7.8 | nodejs node.js Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform | 7.4% | — |
| CVE-2005-1793 | LOW 2.6 | microsoft windows_98se User32.DLL in Microsoft Windows 98SE, and possibly other operating systems, allows local and remote attackers to cause a denial of service (crash) via an icon (.ico) bitmap file with large width and height values. | 7.4% | — |