58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-3782 | MED 4.3 | adobe photoshop_2020 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.2% | — |
| CVE-2020-3781 | MED 4.3 | adobe photoshop_2020 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.2% | — |
| CVE-2020-3778 | MED 4.3 | adobe photoshop_2020 Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.2% | — |
| CVE-2020-3771 | MED 4.3 | adobe photoshop_2020 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2.2% | — |
| CVE-2019-8037 | MED 4.3 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful ex | 2.2% | — |
| CVE-2019-1363 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'. | 2.2% | — |
| CVE-2016-10318 | MED 6.5 | linux linux_kernel A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel before 4.7.4 allows a user to assign an encryption policy to a directory owned by a different user | 2.2% | — |
| CVE-2000-0933 | MED 4.6 | microsoft windows_2000 The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recogniti | 2.2% | — |
| CVE-2019-1463 | MED 5.5 | microsoft office An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1400. | 2.2% | — |
| CVE-2019-1400 | MED 5.5 | microsoft office An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1463. | 2.2% | — |
| CVE-2009-1758 | MED 5.0 | xen xen The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest OS by triggering a segmentatio | 2.2% | — |
| CVE-2003-0258 | HIGH 7.5 | cisco vpn_3000_concentrator_series_software Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication. | 2.2% | — |
| CVE-2022-33647 | HIGH 8.1 | microsoft windows_server_2008 Windows Kerberos Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2021-34474 | HIGH 8.0 | microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2015-0624 | MED 4.3 | cisco content_security_management_appliance The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur444 | 2.2% | — |
| CVE-2019-1442 | MED 5.5 | microsoft sharepoint_server A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerab | 2.2% | — |
| CVE-2018-14616 | MED 5.5 | linux linux_kernel An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c when operating on a file in a corrupted f2fs image. | 2.2% | — |
| CVE-2016-7913 | HIGH 7.8 | canonical ubuntu_linux The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) via vectors involving omission of the firmware name from a certain data str | 2.2% | — |
| CVE-2024-38072 | HIGH 7.5 | microsoft windows_server_2016 Windows Remote Desktop Licensing Service Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-38041 | MED 5.5 | microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability | 2.2% | — |
| CVE-2024-20345 | MED 6.5 | cisco appdynamics_controller A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. This vulnerability is due to insufficient validation of user-suppli | 2.2% | — |
| CVE-2023-29328 | HIGH 8.8 | microsoft teams Microsoft Teams Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2002-0853 | MED 5.0 | cisco vpn_client Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a packet with a zero-length payload. | 2.2% | — |
| CVE-2020-1453 | HIGH 8.6 | microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP | 2.2% | — |
| CVE-2020-1452 | HIGH 8.6 | microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP | 2.2% | — |