58.007 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.007 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-4135 | HIGH 7.5 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated user to send specially crafted packets to cause a denial of service from excessive memory usage. | 2.9% | — |
| CVE-2017-6713 | CRIT 9.8 | cisco elastic_services_controller A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain full access to the affected system. The vulnerability is due to static, default credentials for the Cisco ESC UI that are s | 2.9% | — |
| CVE-2016-9223 | CRIT 9.8 | cisco cloudcenter_orchestrator A vulnerability in the Docker Engine configuration of Cisco CloudCenter Orchestrator (CCO; formerly CliQr) could allow an unauthenticated, remote attacker to install Docker containers with high privileges on the affected system. Affected Products: This vulnera | 2.9% | — |
| CVE-2020-0902 | CRIT 9.8 | microsoft service_fabric An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions, aka 'Service Fabric Elevation of Privilege'. | 2.9% | — |
| CVE-2025-46701 | HIGH 7.3 | apache tomcat Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0 | 2.9% | — |
| CVE-2023-35618 | CRIT 9.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2.9% | — |
| CVE-2018-7250 | MED 5.5 | microsoft windows_7 An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. An uninitialized kernel pool allocation in IOCTL 0xCA002813 allows a local unprivileged | 2.9% | — |
| CVE-2010-0573 | HIGH 8.5 | cisco digital_media_player Unspecified vulnerability on the Cisco Digital Media Player before 5.2 allows remote attackers to hijack the source of (1) video or (2) data for a display via unknown vectors, related to a "content injection" issue, aka Bug ID CSCtc46024. | 2.9% | — |
| CVE-2021-34843 | HIGH 7.8 | foxit pdf_reader This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 2.9% | — |
| CVE-2020-26140 | MED 6.5 | alfa awus036h_firmware An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the ne | 2.9% | — |
| CVE-2015-0702 | HIGH 9.0 | cisco unified_meetingplace Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) allows remote authenticated users to execute arbitrary code by using the languageShortName parameter to upload a file that provides shell | 2.9% | — |
| CVE-2020-9551 | HIGH 7.8 | adobe bridge Adobe Bridge versions 10.0 have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | 2.9% | — |
| CVE-2011-0537 | HIGH 7.5 | mediawiki mediawiki Multiple directory traversal vulnerabilities in (1) languages/Language.php and (2) includes/StubObject.php in MediaWiki 1.8.0 and other versions before 1.16.2, when running on Windows and possibly Novell Netware, allow remote attackers to include and execute a | 2.9% | — |
| CVE-2023-28244 | HIGH 8.1 | microsoft windows_server_2008 Windows Kerberos Elevation of Privilege Vulnerability | 2.9% | — |
| CVE-2022-33874 | CRIT 9.8 | fortinet fortitester An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote atta | 2.9% | — |
| CVE-2022-33872 | CRIT 9.8 | fortinet fortitester An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote a | 2.9% | — |
| CVE-2021-28622 | HIGH 7.8 | adobe animate Adobe Animate version 21.0.6 (and earlier) is affected by an Out-of-bounds Write vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue req | 2.9% | — |
| CVE-2021-27079 | MED 5.7 | microsoft windows_10 Windows Media Photo Codec Information Disclosure Vulnerability | 2.9% | — |
| CVE-2018-15984 | MED 5.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out | 2.9% | — |
| CVE-2019-17562 | CRIT 9.8 | apache cloudstack A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the mac parameter in baremetal virtual router. If you insert an | 2.9% | — |
| CVE-2018-18013 | HIGH 7.8 | citrix xenmobile_server * Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a | 2.9% | — |
| CVE-2010-1571 | HIGH 7.8 | cisco customer_response_solution Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), unspecified 6.0 versions, and 5.0 before 5.0(2)SR3 allows remote attackers to read arbitrary files via a crafted bootstra | 2.9% | — |
| CVE-2018-1199 | MED 5.3 | oracle rapid_planning Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path p | 2.9% | — |
| CVE-2010-1085 | HIGH 7.1 | linux linux_kernel The azx_position_ok function in hda_intel.c in Linux kernel 2.6.33-rc4 and earlier, when running on the AMD780V chip set, allows context-dependent attackers to cause a denial of service (crash) via unknown manipulations that trigger a divide-by-zero error. | 2.9% | — |
| CVE-2021-27052 | MED 5.3 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Information Disclosure Vulnerability | 2.9% | — |