IT
57.918 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.918 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2009-3873 HIGH 9.3 sun jdk The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 4.2%
CVE-2019-6775 HIGH 7.8 foxitsoftware phantompdf This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The 4.2%
CVE-2019-6774 HIGH 7.8 foxitsoftware phantompdf This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The 4.2%
CVE-2022-23742 HIGH 7.8 checkpoint endpoint_security Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpat 4.2%
CVE-2025-29809 HIGH 7.1 microsoft windows_10_1507 Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally. 4.2%
CVE-2024-20683 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 4.2%
CVE-2019-0734 HIGH 8.1 microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresse 4.2%
CVE-2013-3444 HIGH 9.0 cisco application_and_content_networking_system_software The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x 4.2%
CVE-2006-4911 HIGH 7.5 cisco ips_sensor_software Unspecified vulnerability in Cisco IPS 5.0 before 5.0(6p2) and 5.1 before 5.1(2), when running in inline or promiscuous mode, allows remote attackers to bypass traffic inspection via a "crafted sequence of fragmented IP packets". 4.2%
CVE-2020-1504 HIGH 8.8 microsoft excel A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the 4.2%
CVE-2021-36065 HIGH 7.8 adobe photoshop Adobe Photoshop versions 21.2.10 (and earlier) and 22.4.3 (and earlier) are affected by a heap-based buffer overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera 4.2%
CVE-2019-6734 MED 6.5 foxitsoftware phantompdf This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. Th 4.2%
CVE-2026-20871 HIGH 7.8 microsoft windows_10_21h2 Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. 4.2%
CVE-2017-6714 CRIT 9.8 cisco ultra_services_framework_staging_server A vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server could allow an unauthenticated, remote attacker to execute arbitrary shell commands as the Linux root user. The vulnerability is due to improper shell invocations. An attack 4.2%
CVE-2016-4277 MED 6.5 adobe flash_player Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vuln 4.2%
CVE-2018-8020 HIGH 7.4 apache tomcat_native Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client certificates may not be properly identified, 4.2%
CVE-2017-7676 CRIT 9.8 apache ranger Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior. 4.2%
CVE-2011-0533 MED 4.3 apache archiva Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta; and Archiva 1.3.0 through 1.3.3 and 1.0 through 1.22 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, related to the 4.2%
CVE-2022-21994 HIGH 7.8 microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability 4.2%
CVE-2018-8611 HIGH 7.8 microsoft windows_10_1607 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, W 4.2%
CVE-2017-11936 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". 4.2%
CVE-2011-0382 HIGH 10.0 cisco telepresence_recording_server The CGI subsystem on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 allows remote attackers to execute arbitrary commands via a request to TCP port 443, related to a "command injection vulnerability," aka Bug ID CSCtf97221. 4.2%
CVE-2010-2744 HIGH 7.2 microsoft windows_2003_server The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly manage a window class, which allows local users to gain privileges by creating 4.2%
CVE-2017-8508 MED 5.5 microsoft outlook A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats, aka "Microsoft Office Security Feature Bypass Vulnerability". 4.2%
CVE-2009-3457 MED 5.0 cisco ace_web_application_firewall Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a 4.2%