57.613 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.613 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-1458 | MED 6.8 | tweakfs tweakfs_zip_utility Stack-based buffer overflow in Create and Extract Zips TweakFS Zip Utility 1.0 for Flight Simulator X (FSX) allows remote attackers to execute arbitrary code via a long filename in a ZIP archive. | 4.7% | — |
| CVE-2018-14879 | HIGH 7.0 | apple mac_os_x The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file(). | 4.7% | — |
| CVE-2012-0769 | MED 5.0 | adobe flash_player Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.7 on Android 2.x and 3.x; and before 11.1.115.7 on Android 4.x does not properly handle integers, which allows attackers to obtain sensi | 4.7% | — |
| CVE-2017-6214 | HIGH 7.5 | linux linux_kernel The tcp_splice_read function in net/ipv4/tcp.c in the Linux kernel before 4.9.11 allows remote attackers to cause a denial of service (infinite loop and soft lockup) via vectors involving a TCP packet with the URG flag. | 4.7% | — |
| CVE-2019-12425 | HIGH 7.5 | apache ofbiz Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host | 4.7% | — |
| CVE-2020-1319 | HIGH 7.3 | microsoft windows_10 <p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install prog | 4.7% | — |
| CVE-2015-5091 | HIGH 7.8 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to cause a denial of servi | 4.7% | — |
| CVE-2019-18188 | HIGH 7.5 | trendmicro apex_one Trend Micro Apex One could be exploited by an attacker utilizing a command injection vulnerability to extract files from an arbitrary zip file to a specific folder on the Apex One server, which could potentially lead to remote code execution (RCE). The remote | 4.7% | — |
| CVE-2017-1000190 | CRIT 9.1 | apache solr SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on. | 4.7% | — |
| CVE-2019-8238 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20100 and earlier; 2019.010.20099 and earlier versions; 2017.011.30140 and earlier version; 2017.011.30138 and earlier version; 2015.006.30495 and earlier versions; 2015.006.30493 and earlier versions have a Path Trav | 4.7% | — |
| CVE-2020-0869 | HIGH 8.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0801, CVE-2020-0807, CVE-2020-0809. | 4.7% | — |
| CVE-2000-0121 | LOW 3.6 | microsoft windows_nt The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the "Recycle Bin Creation" vulnerability. | 4.7% | — |
| CVE-2026-20840 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 4.7% | — |
| CVE-2023-24939 | HIGH 7.5 | microsoft windows_10_1507 Server for NFS Denial of Service Vulnerability | 4.7% | — |
| CVE-2014-3412 | HIGH 10.0 | juniper junos_space Unspecified vulnerability in Juniper Junos Space before 13.3R1.8, when the firewall in disabled, allows remote attackers to execute arbitrary commands via unspecified vectors. | 4.7% | — |
| CVE-2023-21607 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exp | 4.7% | — |
| CVE-2021-41973 | MED 6.5 | apache mina In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update M | 4.7% | — |
| CVE-2011-0962 | MED 4.3 | cisco unified_operations_manager Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Device Center in Cisco Unified Operations Manager (CUOM) before 8.6 allows remote attackers to inject arbitrary web script or HTML via the tag | 4.7% | — |
| CVE-2018-8320 | MED 4.3 | microsoft windows_10 A security feature bypass vulnerability exists in DNS Global Blocklist feature, aka "Windows DNS Security Feature Bypass Vulnerability." This affects Windows Server 2012 R2, Windows Server 2008, Windows Server 2012, Windows Server 2019, Windows Server 2016, Wi | 4.7% | — |
| CVE-2019-6728 | MED 6.5 | foxitsoftware phantompdf This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The sp | 4.6% | — |
| CVE-2020-3258 | CRIT 9.8 | cisco ios Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker or an authenticated, local atta | 4.6% | — |
| CVE-2019-1200 | HIGH 7.8 | microsoft office A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security contex | 4.6% | — |
| CVE-2019-1199 | HIGH 7.8 | microsoft office A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current | 4.6% | — |
| CVE-2011-2732 | MED 4.3 | vmware springsource_spring_security CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the spring-security-red | 4.6% | — |
| CVE-2020-1961 | CRIT 9.8 | apache syncope Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (RCE) was discovered. | 4.6% | — |