57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-53197 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_configur | 3.6% | |
| CVE-2022-26915 | HIGH 7.5 | microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability | 3.6% | — |
| CVE-2020-9486 | HIGH 7.5 | apache nifi In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plainte | 3.6% | — |
| CVE-2018-3276 | MED 4.9 | canonical ubuntu_linux Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker wi | 3.6% | — |
| CVE-2019-6757 | HIGH 7.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.4.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 3.6% | — |
| CVE-2020-9670 | CRIT 9.8 | adobe creative_cloud_desktop_application Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to privilege escalation. | 3.6% | — |
| CVE-2019-1338 | MED 5.9 | microsoft windows_7 A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLMv2 protection if a client is also sending LMv2 responses, aka 'Windows NTLM Security Feature Bypass Vulnerability'. | 3.6% | — |
| CVE-2018-19723 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. Note: A different vulnerability tha | 3.6% | — |
| CVE-2020-27860 | HIGH 7.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.1.35811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 3.6% | — |
| CVE-2020-3748 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution . | 3.6% | — |
| CVE-2015-2554 | HIGH 7.2 | microsoft windows_10 The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Object Reference Elevation of Privilege Vulnerability." | 3.6% | — |
| CVE-2011-2107 | MED 4.3 | adobe acrobat Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.22 and earlier on Android, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related | 3.6% | — |
| CVE-2011-4186 | HIGH 9.3 | novell iprint Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code via a crafted client-file-name parameter in a printer-url, a different vulnerability than CVE-2011-1705. | 3.6% | — |
| CVE-2022-24464 | HIGH 7.5 | fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability | 3.6% | — |
| CVE-2020-1467 | CRIT 10.0 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, an attacker would | 3.5% | — |
| CVE-2009-4764 | HIGH 9.3 | adobe acrobat_reader Adobe Reader 8.x and 9.x on Windows is able to execute EXE files that are embedded in a PDF document, which makes it easier for remote attackers to trick users into executing arbitrary code via a crafted document. | 3.5% | — |
| CVE-2017-2957 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the JavaScript engine, related to collaboration functionality. Successful exploitation could lead to arbit | 3.5% | — |
| CVE-2023-35380 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 3.5% | — |
| CVE-2011-0610 | HIGH 9.3 | adobe acrobat The CoolType library in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allows remote attacker | 3.5% | — |
| CVE-2002-1547 | MED 5.0 | juniper netscreen_screenos Netscreen running ScreenOS 4.0.0r6 and earlier allows remote attackers to cause a denial of service via a malformed SSH packet to the Secure Command Shell (SCS) management interface, as demonstrated via certain CRC32 exploits, a different vulnerability than CV | 3.5% | — |
| CVE-2025-47732 | HIGH 8.7 | microsoft dataverse Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. | 3.5% | — |
| CVE-2006-20001 | HIGH 7.5 | apache http_server A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier. | 3.5% | — |
| CVE-2020-17019 | HIGH 7.8 | microsoft office Microsoft Excel Remote Code Execution Vulnerability | 3.5% | — |
| CVE-2024-30035 | HIGH 7.8 | microsoft windows_10_1809 Windows DWM Core Library Elevation of Privilege Vulnerability | 3.5% | — |
| CVE-2012-4078 | HIGH 8.5 | cisco unified_computing_system The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote authenticated users to bypass an unspecified authentication step via SSH port forwarding, aka Bug ID CSCtg17656 | 3.5% | — |