58.070 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.070 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2001-0919 | MED 5.1 | microsoft internet_explorer Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript. | 2.7% | — |
| CVE-2022-30159 | MED 5.5 | microsoft office_online_server Microsoft Office Information Disclosure Vulnerability | 2.7% | — |
| CVE-2021-1362 | HIGH 8.8 | cisco prime_license_manager A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, and Cisco Prime License M | 2.7% | — |
| CVE-2020-12388 | CRIT 10.0 | mozilla firefox The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76. | 2.7% | — |
| CVE-2019-12416 | MED 6.1 | apache deltaspike we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrategy which is not the default. | 2.7% | — |
| CVE-2018-0391 | MED 6.5 | cisco prime_collaboration A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to cause the system to become inoperable. The vulnerability is due to insufficient validation of a password change request. | 2.7% | — |
| CVE-2022-26926 | HIGH 7.8 | microsoft windows_10 Windows Address Book Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-43215 | CRIT 9.8 | microsoft windows_10 iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution | 2.7% | — |
| CVE-2019-7047 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.7% | — |
| CVE-2019-7038 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.7% | — |
| CVE-2019-7036 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.7% | — |
| CVE-2018-19722 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.7% | — |
| CVE-2006-1961 | HIGH 7.5 | cisco ciscoworks_2000_service_management_solution Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Managem | 2.7% | — |
| CVE-1999-1235 | MED 4.6 | microsoft internet_explorer Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to | 2.7% | — |
| CVE-2021-41365 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2019-0204 | HIGH 7.8 | apache mesos A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A | 2.7% | — |
| CVE-2016-7295 | MED 5.5 | microsoft windows_10 The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local user | 2.7% | — |
| CVE-2016-7258 | MED 5.5 | microsoft windows_10 The kernel in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 mishandles page-fault system calls, which allows local users to obtain sensitive information from arbitrary processes via a crafted application, aka "Windows Kernel Memory Address | 2.7% | — |
| CVE-2015-6313 | HIGH 7.5 | sun opensolaris Cisco TelePresence Server 4.1(2.29) through 4.2(4.17) on 7010; Mobility Services Engine (MSE) 8710; Multiparty Media 310, 320, and 820; and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (memory consumption or device reload) | 2.7% | — |
| CVE-2021-35474 | CRIT 9.8 | apache traffic_server Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. | 2.7% | — |
| CVE-2021-34449 | HIGH 7.0 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2005-3057 | HIGH 10.0 | fortinet fortigate The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has bee | 2.7% | — |
| CVE-2023-26424 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in | 2.7% | — |
| CVE-2023-26420 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in | 2.7% | — |
| CVE-2023-26419 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in | 2.7% | — |