57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-31813 | CRIT 9.8 | apache http_server Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application. | 3.5% | — |
| CVE-2021-27577 | HIGH 7.5 | apache traffic_server Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. | 3.5% | — |
| CVE-2018-1000004 | MED 5.9 | linux linux_kernel In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race condition vulnerability exists in the sound system, this can lead to a deadlock and denial of service condition. | 3.5% | — |
| CVE-2014-2401 | MED 5.0 | ibm forms_viewer Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality via unknown vectors related to 2D. | 3.5% | — |
| CVE-2024-22252 | CRIT 9.3 | vmware esxi VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runn | 3.5% | — |
| CVE-2017-0256 | MED 5.3 | microsoft asp.net_model_view_controller A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | 3.5% | — |
| CVE-2005-3180 | MED 5.0 | linux linux_kernel The Orinoco driver (orinoco.c) in Linux kernel 2.6.13 and earlier does not properly clear memory from a previously used packet whose length is increased, which allows remote attackers to obtain sensitive information. | 3.5% | — |
| CVE-2009-1792 | HIGH 9.3 | stonetrip s3dplayer_standalone The system.openURL function in StoneTrip Ston3D StandalonePlayer (aka S3DPlayer StandAlone) 1.6.2.4 and 1.7.0.1 and WebPlayer (aka S3DPlayer Web) 1.6.0.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the first argument (the | 3.5% | — |
| CVE-2021-27058 | HIGH 7.8 | microsoft 365_apps Microsoft Office ClickToRun Remote Code Execution Vulnerability | 3.5% | — |
| CVE-2021-26433 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 3.5% | — |
| CVE-2015-2114 | MED 6.8 | hp support_solution_framework HP Support Solution Framework before 11.51.0049 allows remote attackers to download an arbitrary program onto a client machine and execute this program via unspecified vectors. | 3.5% | — |
| CVE-2012-0803 | CRIT 9.8 | apache cxf The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as part of a SOAP request. | 3.5% | — |
| CVE-2008-0600 | HIGH 7.2 | linux linux_kernel The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different vulnerability | 3.5% | — |
| CVE-2021-28553 | HIGH 8.8 | adobe acrobat Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary | 3.5% | — |
| CVE-2019-7079 | HIGH 8.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code executi | 3.5% | — |
| CVE-2019-19447 | HIGH 7.8 | linux linux_kernel In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c. | 3.5% | — |
| CVE-2023-21552 | HIGH 7.8 | microsoft windows_10_1607 Windows GDI Elevation of Privilege Vulnerability | 3.5% | — |
| CVE-2021-21044 | HIGH 7.8 | adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an Out-of-bounds Write vulnerability when parsing a crafted jpeg file. An unauthenticated attacker could leverage th | 3.5% | — |
| CVE-2020-24588 | LOW 3.5 | arista c-100_firmware The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU fr | 3.5% | — |
| CVE-2019-0813 | CRIT 9.8 | microsoft windows_admin_center An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations, aka 'Windows Admin Center Elevation of Privilege Vulnerability'. | 3.5% | — |
| CVE-2025-49125 | HIGH 7.5 | apache tomcat Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That pat | 3.5% | — |
| CVE-2019-0959 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vuln | 3.5% | — |
| CVE-2009-3902 | MED 5.0 | cherokee cherokee_httpd Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (slash backslash dot dot) in the URL. | 3.5% | — |
| CVE-2000-1027 | MED 5.0 | cisco pix_firewall_software Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive mode is established. | 3.5% | — |
| CVE-2022-28242 | HIGH 7.8 | adobe acrobat Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of thi | 3.5% | — |