57.551 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-1999-1222 | MED 5.0 | microsoft windows_nt Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup. | 5.0% | — |
| CVE-2012-0174 | LOW 1.7 | microsoft windows_7 Windows Firewall in tcpip.sys in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly enforce firewall rules for outbound broadcast packets, which allows remote attackers to obtain potentially sensi | 5.0% | — |
| CVE-2019-13565 | HIGH 7.5 | apple mac_os_x An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for | 5.0% | — |
| CVE-2017-8637 | MED 5.3 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to bypass Arbitrary Code Guard (ACG) due to how Microsoft Edge accesses memory in code compiled by the Edge Just-In-Time (JIT) compiler, aka "Scripting Engine Security Feature Bypass Vulnerability" | 5.0% | — |
| CVE-1999-0227 | MED 5.0 | microsoft windows_nt Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service. | 5.0% | — |
| CVE-2009-2696 | MED 4.3 | apache tomcat Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web | 5.0% | — |
| CVE-2026-50507 | MED 6.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 5.0% | — |
| CVE-2018-1259 | HIGH 7.5 | broadcom spring_data_commons Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying lib | 5.0% | — |
| CVE-2019-16765 | HIGH 7.4 | microsoft codeql If an attacker can get a user to open a specially prepared directory tree as a workspace in Visual Studio Code with the CodeQL extension active, arbitrary code of the attacker's choosing may be executed on the user's behalf. This is fixed in version 1.0.1 of t | 5.0% | — |
| CVE-2016-3320 | MED 4.9 | fedoraproject fedora Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow attackers to bypass the Secure Boot protection mechanism by leveraging (1) administrative or (2) physical access to install a crafted boot manager, aka " | 5.0% | — |
| CVE-2022-34226 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memor | 5.0% | — |
| CVE-2019-10744 | CRIT 9.1 | f5 big-ip_access_policy_manager Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload. | 5.0% | — |
| CVE-2011-0589 | HIGH 9.3 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2 | 5.0% | — |
| CVE-2012-1622 | CRIT 9.8 | apache ofbiz Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors. | 5.0% | — |
| CVE-2020-3740 | CRIT 9.8 | adobe framemaker Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | 5.0% | — |
| CVE-2018-8482 | LOW 3.1 | microsoft windows_10 An information disclosure vulnerability exists when Windows Media Player improperly discloses file information, aka "Windows Media Player Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008 | 5.0% | — |
| CVE-2018-8481 | LOW 3.1 | microsoft windows_10 An information disclosure vulnerability exists when Windows Media Player improperly discloses file information, aka "Windows Media Player Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008 | 5.0% | — |
| CVE-2019-7061 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure | 5.0% | — |
| CVE-2019-0723 | MED 5.8 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host s | 5.0% | — |
| CVE-2019-0718 | MED 5.8 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host s | 5.0% | — |
| CVE-2019-0715 | MED 5.8 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host s | 5.0% | — |
| CVE-2019-0714 | MED 5.8 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host s | 5.0% | — |
| CVE-2018-6968 | CRIT 10.0 | vmware airwatch_agent The VMware AirWatch Agent for Android prior to 8.2 and AirWatch Agent for Windows Mobile prior to 6.5.2 contain a remote code execution vulnerability in real time File Manager capabilities. This vulnerability may allow for unauthorized creation and execution o | 5.0% | — |
| CVE-2016-4182 | HIGH 8.8 | adobe flash_player Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different v | 5.0% | — |
| CVE-2017-3074 | HIGH 8.8 | adobe flash_player Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Graphics class. Successful exploitation could lead to arbitrary code execution. | 5.0% | — |