57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-2507 | HIGH 7.2 | microsoft windows_10 The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a craft | 3.4% | — |
| CVE-2025-29972 | CRIT 9.9 | microsoft azure_storage_resource_provider Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. | 3.4% | — |
| CVE-2016-6958 | CRIT 9.8 | adobe acrobat Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to bypass intended access restrictions via unspecified vect | 3.4% | — |
| CVE-2020-1231 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282, CVE | 3.4% | — |
| CVE-2017-8758 | MED 6.1 | microsoft exchange_server Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability." | 3.4% | — |
| CVE-2015-6109 | LOW 2.1 | microsoft windows_10 The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and consequently discover a driver base address, via a crafted application, aka "Windows Kern | 3.4% | — |
| CVE-2019-1136 | HIGH 8.1 | microsoft exchange_server An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. | 3.4% | — |
| CVE-2022-28239 | HIGH 7.8 | adobe acrobat Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory st | 3.4% | — |
| CVE-2021-33757 | MED 5.3 | microsoft windows_10 Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability | 3.4% | — |
| CVE-2019-1194 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current u | 3.4% | — |
| CVE-2018-0443 | HIGH 7.5 | cisco wireless_lan_controller_software A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilit | 3.4% | — |
| CVE-2024-38237 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | 3.4% | — |
| CVE-2017-7678 | MED 6.1 | apache spark In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link that points to a shared Spark cluster and submits data including MHTML to the Spark master, or history server. Thi | 3.4% | — |
| CVE-2015-0644 | HIGH 7.8 | cisco ios_xe AppNav in Cisco IOS XE 3.8 through 3.10 before 3.10.3S, 3.11 before 3.11.3S, 3.12 before 3.12.1S, 3.13 before 3.13.0S, 3.14 before 3.14.0S, and 3.15 before 3.15.0S allows remote attackers to execute arbitrary code or cause a denial of service (device reload) v | 3.4% | — |
| CVE-2005-3110 | LOW 2.6 | linux linux_kernel Race condition in ebtables netfilter module (ebtables.c) in Linux 2.6, when running on an SMP system that is operating under a heavy load, might allow remote attackers to cause a denial of service (crash) via a series of packets that cause a value to be modifi | 3.4% | — |
| CVE-2016-1335 | HIGH 7.5 | cisco asr_5000_series_software The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key authentication configuration, which allows remote authenticated users to gain privileges by establishing a connecti | 3.4% | — |
| CVE-2017-6883 | MED 4.7 | foxitsoftware foxit_reader The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vulnerabi | 3.4% | — |
| CVE-2016-7185 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted appl | 3.4% | — |
| CVE-2018-0239 | HIGH 7.5 | cisco staros A vulnerability in the egress packet processing functionality of the Cisco StarOS operating system for Cisco Aggregation Services Router (ASR) 5700 Series devices and Virtualized Packet Core (VPC) System Software could allow an unauthenticated, remote attacker | 3.4% | — |
| CVE-2011-1581 | HIGH 9.0 | linux linux_kernel The bond_select_queue function in drivers/net/bonding/bond_main.c in the Linux kernel before 2.6.39, when a network device with a large number of receive queues is installed but the default tx_queues setting is used, does not properly restrict queue indexes, w | 3.4% | — |
| CVE-2003-1342 | MED 5.0 | trend_micro virus_control_system Trend Micro Virus Control System (TVCS) 1.8 running with IIS allows remote attackers to cause a denial of service (memory consumption) in IIS via multiple URL requests for ActiveSupport.exe. | 3.4% | — |
| CVE-2002-1101 | MED 5.0 | cisco vpn_3000_concentrator_series_software Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name. | 3.4% | — |
| CVE-2019-1899 | MED 5.3 | cisco rv110w_firmware A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network. The vulnerability is due to improper authorization of an HT | 3.4% | — |
| CVE-2020-16904 | MED 5.3 | microsoft azure_functions <p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p> <p>An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.</p> <p>This security | 3.4% | — |
| CVE-2010-1577 | HIGH 7.8 | cisco content_delivery_system Directory traversal vulnerability in Cisco Internet Streamer, as used in Cisco Content Delivery System (CDS) 2.2.x, 2.3.x, 2.4.x, and 2.5.x before 2.5.7 allows remote attackers to read arbitrary files via a crafted URL. | 3.4% | — |