58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2012-4659 | HIGH 7.1 | cisco 5500_series_adaptive_security_appliance The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.2 before 8.2(5.30) and 8.3 before 8.3(2.34) al | 2.6% | — |
| CVE-2012-4168 | MED 4.3 | adobe air Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe AIR before 3.4.0.2540; | 2.6% | — |
| CVE-2007-4671 | MED 6.8 | apple safari Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to "alter or access" HTTPS content via an HTTP session with a crafted web page that causes Ja | 2.6% | — |
| CVE-2023-38243 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such a | 2.6% | — |
| CVE-2023-33134 | HIGH 8.8 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2022-24498 | MED 6.5 | microsoft windows_10 Windows iSCSI Target Service Information Disclosure Vulnerability | 2.6% | — |
| CVE-2022-38398 | MED 5.3 | apache batik Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14. | 2.6% | — |
| CVE-2022-26919 | HIGH 8.1 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2022-23254 | MED 4.9 | microsoft powerbi-client_js_sdk Microsoft Power BI Information Disclosure Vulnerability | 2.6% | — |
| CVE-2021-31949 | HIGH 7.3 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2018-1000621 | HIGH 8.1 | mycroft mycroft-core Mycroft AI mycroft-core version 18.2.8b and earlier contains a Incorrect Access Control vulnerability in Websocket configuration that can result in code execution. This impacts ONLY the Mycroft for Linux and "non-enclosure" installs - Mark 1 and Picroft unaffe | 2.6% | — |
| CVE-2011-2538 | HIGH 7.2 | cisco telepresence_video_communication_server Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands. | 2.6% | — |
| CVE-2021-0254 | CRIT 9.8 | juniper junos A buffer size validation vulnerability in the overlayd service of Juniper Networks Junos OS may allow an unauthenticated remote attacker to send specially crafted packets to the device, triggering a partial Denial of Service (DoS) condition, or leading to remo | 2.6% | — |
| CVE-2019-18807 | HIGH 7.5 | linux linux_kernel Two memory leaks in the sja1105_static_config_upload() function in drivers/net/dsa/sja1105/sja1105_spi.c in the Linux kernel before 5.3.5 allow attackers to cause a denial of service (memory consumption) by triggering static_config_buf_prepare_for_upload() or | 2.6% | — |
| CVE-2018-0864 | MED 5.4 | microsoft sharepoint_server SharePoint Project Server 2013 and SharePoint Enterprise Server 2016 allow an information disclosure vulnerability due to how web requests are handled, aka "Microsoft SharePoint Information Disclosure Vulnerability". | 2.6% | — |
| CVE-2008-1155 | HIGH 10.0 | cisco network_admission_control Cisco Network Admission Control (NAC) Appliance 3.5.x, 3.6.x before 3.6.4.4, 4.0.x before 4.0.6, and 4.1.x before 4.1.2 allows remote attackers to obtain the shared secret for the Clean Access Server (CAS) and Clean Access Manager (CAM) by sniffing error logs. | 2.6% | — |
| CVE-2007-5382 | HIGH 10.0 | cisco wireless_control_system The conversion utility for converting CiscoWorks Wireless LAN Solution Engine (WLSE) 4.1.91.0 and earlier to Cisco Wireless Control System (WCS) creates administrator accounts with default usernames and passwords, which allows remote attackers to gain privileg | 2.6% | — |
| CVE-2007-2036 | HIGH 10.0 | cisco wireless_lan_controller_software The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default read-only community public, and the default read-write community private, which allows remote attackers to read and modify SNMP variables, aka Bug ID CSCse02384 | 2.6% | — |
| CVE-2024-35264 | HIGH 8.1 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2023-21604 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Ex | 2.6% | — |
| CVE-2011-3272 | HIGH 7.8 | cisco ios The IP Service Level Agreement (IP SLA) functionality in Cisco IOS 15.1, and IOS XE 2.1.x through 3.3.x, allows remote attackers to cause a denial of service (memory corruption and device reload) via malformed IP SLA packets, aka Bug ID CSCtk67073. | 2.6% | — |
| CVE-2023-36780 | HIGH 7.2 | microsoft skype_for_business_server Skype for Business Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2018-3185 | MED 5.5 | canonical ubuntu_linux Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multipl | 2.6% | — |
| CVE-2015-2382 | LOW 2.1 | microsoft windows_8 win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Win32k Information Dis | 2.6% | — |
| CVE-2015-2381 | LOW 2.1 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Win32k Information Dis | 2.6% | — |