57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-12247 | HIGH 7.1 | foxitsoftware phantompdf In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information from an out-of-bounds read because a text-string index continues to be used after splitting a string into two parts. A crash may also occur. | 3.6% | — |
| CVE-2011-3251 | HIGH 9.3 | apple quicktime Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted TKHD atoms in a QuickTime movie file. | 3.6% | — |
| CVE-2018-4927 | HIGH 7.8 | adobe indesign Adobe InDesign versions 13.0 and below have an exploitable Untrusted Search Path vulnerability. Successful exploitation could lead to local privilege escalation. | 3.6% | — |
| CVE-2001-0760 | MED 5.0 | citrix nfuse Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field. | 3.6% | — |
| CVE-2019-1385 | HIGH 7.8 | ransomware microsoft windows_10_1709 An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially craf | 3.6% | |
| CVE-2023-21688 | HIGH 7.8 | microsoft windows_10_1507 NT OS Kernel Elevation of Privilege Vulnerability | 3.6% | — |
| CVE-2010-1086 | HIGH 7.8 | debian debian_linux The ULE decapsulation functionality in drivers/media/dvb/dvb-core/dvb_net.c in dvb-core in Linux kernel 2.6.33 and earlier allows attackers to cause a denial of service (infinite loop) via a crafted MPEG2-TS frame, related to an invalid Payload Pointer ULE. | 3.6% | — |
| CVE-2014-2198 | HIGH 10.0 | cisco unified_cdm_platform_software Cisco Unified Communications Domain Manager (CDM) in Unified CDM Platform Software before 4.4.2 has a hardcoded SSH private key, which makes it easier for remote attackers to obtain access to the support and root accounts by extracting this key from a binary f | 3.6% | — |
| CVE-2013-6979 | MED 5.4 | cisco ios_xe The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authentication by leveraging access to a 192.168.x.2 source IP address, | 3.6% | — |
| CVE-2025-20303 | MED 5.4 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient vali | 3.6% | — |
| CVE-2014-0524 | HIGH 10.0 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0522, CVE-2014- | 3.6% | — |
| CVE-2014-0522 | HIGH 10.0 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0523, CVE-2014- | 3.6% | — |
| CVE-2021-1716 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 3.6% | — |
| CVE-2021-1715 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 3.6% | — |
| CVE-2019-0909 | HIGH 7.5 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 3.6% | — |
| CVE-2017-6652 | HIGH 7.5 | cisco telepresence_ix5000 A vulnerability in the web framework of the Cisco TelePresence IX5000 Series could allow an unauthenticated, remote attacker to access arbitrary files on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit t | 3.6% | — |
| CVE-2018-15990 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an use | 3.6% | — |
| CVE-2017-5636 | CRIT 9.8 | apache nifi In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injection attack where a carefully crafted username could impersonate another user and gain their permissions on a repl | 3.6% | — |
| CVE-2014-0581 | HIGH 10.0 | adobe air Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execu | 3.6% | — |
| CVE-2014-0576 | HIGH 10.0 | adobe air Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execu | 3.6% | — |
| CVE-2014-4323 | HIGH 7.5 | linux linux_kernel The mdp_lut_hw_update function in drivers/video/msm/mdp.c in the MDP display driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain start and length valu | 3.6% | — |
| CVE-2009-3096 | HIGH 10.0 | hp performance_insight Multiple unspecified vulnerabilities in HP Performance Insight 5.3 allow remote attackers to have an unknown impact, related to (1) a "Remote exploit" on Windows platforms, and (2) a "Remote preauthentication exploit" on the Windows Server 2003 SP2 platform, a | 3.6% | — |
| CVE-2005-4583 | MED 4.3 | vmware esx Unspecified vulnerability in the Management Interface in VMware ESX Server 2.x up to 2.5.x before 24 December 2005 allows "remote code execution in the Web browser" via unspecified attack vectors, probably related to cross-site scripting (XSS). | 3.6% | — |
| CVE-2021-26879 | HIGH 7.5 | microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 3.6% | — |
| CVE-2019-19049 | HIGH 7.5 | linux linux_kernel A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a. NOTE: third pa | 3.6% | — |