57.574 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.574 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2002-0367 | HIGH 7.8 | microsoft windows_2000 smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstr | 4.9% | |
| CVE-2020-24410 | HIGH 7.8 | adobe illustrator Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing crafted PDF files. This could result in a read past the end of an allocated memory structure, potentially resulting in arbitrary code execution in the | 4.9% | — |
| CVE-2020-24409 | HIGH 7.8 | adobe illustrator Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing crafted PDF files. This could result in a read past the end of an allocated memory structure, potentially resulting in arbitrary code execution in the | 4.9% | — |
| CVE-2009-1123 | HIGH 7.8 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, ak | 4.9% | |
| CVE-2018-19713 | HIGH 8.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use | 4.9% | — |
| CVE-1999-0576 | HIGH 7.5 | microsoft windows_nt A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories. | 4.9% | — |
| CVE-2022-20711 | CRIT 10.0 | cisco rv340_firmware Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot | 4.9% | — |
| CVE-2012-4446 | MED 6.8 | apache qpid The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via | 4.9% | — |
| CVE-2021-41368 | MED 6.1 | microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability | 4.9% | — |
| CVE-2019-1089 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel improperly handles an RPC request. To exploit this vulnerability, a low level authenticated attacker could run a specially crafted application. The security upda | 4.9% | — |
| CVE-2023-36799 | MED 6.5 | microsoft .net .NET Core and Visual Studio Denial of Service Vulnerability | 4.9% | — |
| CVE-2020-0922 | HIGH 8.8 | microsoft windows_10 <p>A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system.</p> <p>To exploit the vulnerability, | 4.9% | — |
| CVE-2021-1723 | HIGH 7.5 | fedoraproject fedora ASP.NET Core and Visual Studio Denial of Service Vulnerability | 4.9% | — |
| CVE-2023-44371 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in | 4.9% | — |
| CVE-2022-47941 | HIGH 7.5 | linux linux_kernel An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions, aka a memory leak. | 4.9% | — |
| CVE-2020-1583 | HIGH 8.8 | microsoft 365_apps An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, a | 4.9% | — |
| CVE-2020-10910 | HIGH 7.8 | foxitsoftware phantompdf This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 4.9% | — |
| CVE-2020-10907 | HIGH 7.8 | foxitsoftware phantompdf This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 4.9% | — |
| CVE-2020-10906 | HIGH 7.8 | foxitsoftware phantompdf This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 4.9% | — |
| CVE-2020-10900 | HIGH 7.8 | foxitsoftware phantompdf This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 4.9% | — |
| CVE-2020-0997 | HIGH 7.8 | microsoft windows_10 <p>A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user i | 4.9% | — |
| CVE-2007-0481 | HIGH 7.8 | cisco ios_transmission_control_protocol Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header. | 4.9% | — |
| CVE-2016-6441 | CRIT 9.8 | cisco ios_xe A vulnerability in the Transaction Language 1 (TL1) code of Cisco ASR 900 Series routers could allow an unauthenticated, remote attacker to cause a reload of, or remotely execute code on, the affected system. This vulnerability affects Cisco ASR 900 Series Agg | 4.9% | — |
| CVE-2014-0453 | MED 4.0 | canonical ubuntu_linux Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security. | 4.9% | — |
| CVE-2016-0141 | MED 6.5 | microsoft office The Visual Basic macros in Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 export a certificate-store private key during a document-save operation, which allows attackers to obtain sensitive information via unspecified vectors, aka "Microsoft Informati | 4.9% | — |