58.015 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.015 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-21925 | MED 5.3 | microsoft windows_7 Windows BackupKey Remote Protocol Security Feature Bypass Vulnerability | 2.9% | — |
| CVE-2022-21924 | MED 5.3 | microsoft windows_10 Workstation Service Remote Protocol Security Feature Bypass Vulnerability | 2.9% | — |
| CVE-2020-1951 | MED 5.5 | apache tika A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23. | 2.9% | — |
| CVE-2008-4933 | HIGH 7.8 | linux linux_kernel Buffer overflow in the hfsplus_find_cat function in fs/hfsplus/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfsplus filesystem image with an invalid catalog namelength | 2.9% | — |
| CVE-2007-5587 | MED 6.9 | macrovision safedisc Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and | 2.9% | — |
| CVE-2021-31522 | CRIT 9.8 | apache kylin Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions. | 2.9% | — |
| CVE-2008-5537 | HIGH 9.3 | pctools pctools_antivirus PC Tools AntiVirus 4.4.2.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a | 2.9% | — |
| CVE-2008-5523 | HIGH 9.3 | avast avast_antivirus avast! antivirus 4.8.1281.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a | 2.9% | — |
| CVE-2008-5522 | HIGH 9.3 | avg antivirus AVG Anti-Virus 8.0.0.161, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .t | 2.9% | — |
| CVE-2022-27479 | CRIT 9.8 | apache superset Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue. | 2.9% | — |
| CVE-2019-1687 | HIGH 7.5 | cisco adaptive_security_appliance_software A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to restart unexpectedly, resulting in a de | 2.9% | — |
| CVE-2021-27263 | LOW 3.3 | foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 2.9% | — |
| CVE-2020-4001 | CRIT 9.8 | vmware sd-wan_orchestrator The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack. | 2.9% | — |
| CVE-2007-0397 | MED 6.4 | cisco adaptive_security_appliance_device_manager The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attacker | 2.9% | — |
| CVE-2020-13958 | HIGH 7.8 | apache openoffice A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks pointing to an executable on the target users file system. These hyperlinks can be triggered unconditionally. In fixed versions no internal pr | 2.9% | — |
| CVE-2019-10089 | MED 6.1 | apache jspwiki On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get som | 2.9% | — |
| CVE-2018-19452 | HIGH 7.8 | foxitsoftware foxit_pdf_sdk_activex A use after free in the TextBox field Mouse Enter action in IReader_ContentProvider can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031. An attacker can leverage this to gain remote code execution. Relative to CVE-20 | 2.9% | — |
| CVE-2008-1214 | HIGH 7.5 | numara footprints MRcgi/MRProcessIncomingForms.pl in Numara FootPrints 8.1 on Linux allows remote attackers to execute arbitrary code via shell metacharacters in the PROJECTNUM parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from | 2.9% | — |
| CVE-2014-6032 | MED 5.5 | f5 big-ip_advanced_firewall_manager Multiple XML External Entity (XXE) vulnerabilities in the Configuration utility in F5 BIG-IP LTM, ASM, GTM, and Link Controller 11.0 through 11.6.0 and 10.0.0 through 10.2.4, AAM 11.4.0 through 11.6.0, ARM 11.3.0 through 11.6.0, Analytics 11.0.0 through 11.6.0 | 2.9% | — |
| CVE-2024-20672 | HIGH 7.5 | microsoft .net .NET Denial of Service Vulnerability | 2.9% | — |
| CVE-2019-16413 | HIGH 7.5 | linux linux_kernel An issue was discovered in the Linux kernel before 5.0.4. The 9p filesystem did not protect i_size_write() properly, which causes an i_size_read() infinite loop and denial of service on SMP systems. | 2.9% | — |
| CVE-2018-5487 | CRIT 9.8 | netapp oncommand_unified_manager NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service bound to the network, and are susceptible to unauthenticated remote code execution. | 2.9% | — |
| CVE-2018-3958 | HIGH 7.8 | foxitsoftware phantompdf A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Subject property of the this.info object. An attacker needs to trick the user to ope | 2.9% | — |
| CVE-2018-3957 | HIGH 7.8 | foxitsoftware phantompdf A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Keywords property of the this.info object. An attacker needs to trick the user to op | 2.9% | — |
| CVE-2018-0348 | HIGH 7.2 | cisco vbond_orchestrator A vulnerability in the CLI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this | 2.9% | — |