57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-3965 | HIGH 7.8 | foxitsoftware phantompdf An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code exec | 6.0% | — |
| CVE-2017-6627 | HIGH 7.5 | cisco ios A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a | 6.0% | |
| CVE-2016-6932 | HIGH 8.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than | 6.0% | — |
| CVE-2016-6930 | HIGH 8.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than | 6.0% | — |
| CVE-2016-6929 | HIGH 8.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than | 6.0% | — |
| CVE-2016-6927 | HIGH 8.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than | 6.0% | — |
| CVE-2016-6926 | HIGH 8.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than | 6.0% | — |
| CVE-2016-6925 | HIGH 8.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than | 6.0% | — |
| CVE-2016-6923 | HIGH 8.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than | 6.0% | — |
| CVE-2016-6921 | HIGH 8.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than | 6.0% | — |
| CVE-2016-4279 | HIGH 8.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than | 6.0% | — |
| CVE-2016-4272 | HIGH 8.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than | 6.0% | — |
| CVE-2016-4174 | HIGH 8.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than | 6.0% | — |
| CVE-2016-4173 | HIGH 8.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than | 6.0% | — |
| CVE-2001-1219 | MED 5.0 | microsoft internet_explorer Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location. | 6.0% | — |
| CVE-2017-9801 | HIGH 7.5 | apache commons_email When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP headers. | 6.0% | — |
| CVE-2017-0192 | MED 4.3 | microsoft windows_10 The Adobe Type Manager Font Driver (ATMFD.dll) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold , 1511, 1607, and 1703 allows an attacker to gai | 6.0% | — |
| CVE-2022-24547 | HIGH 7.8 | microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability | 6.0% | — |
| CVE-2016-7020 | HIGH 8.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than | 6.0% | — |
| CVE-2021-37608 | CRIT 9.8 | apache ofbiz Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at https://issues.ap | 6.0% | — |
| CVE-2021-45029 | CRIT 9.8 | apache shenyu Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | 6.0% | — |
| CVE-1999-0179 | MED 5.0 | microsoft windows_95 Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share. | 6.0% | — |
| CVE-2019-1006 | HIGH 7.5 | microsoft .net_framework An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'. | 6.0% | — |
| CVE-2014-2781 | HIGH 7.6 | microsoft windows_7 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the exchange of keyboard and mouse data between programs at different | 6.0% | — |
| CVE-1999-0590 | HIGH 10.0 | apple macos A system does not present an appropriate legal message or warning to a user who is accessing it. | 6.0% | — |