56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.705 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-1999-0016 | MED 5.0 | cisco ios Land IP denial of service. | 95.7% | — |
| CVE-2018-1273 | CRIT 9.8 | ransomware apache ignite Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supp | 95.7% | |
| CVE-2019-1663 | CRIT 9.8 | cisco rv110w_firmware A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary cod | 95.7% | — |
| CVE-2016-2183 | HIGH 7.5 | cisco content_security_management_appliance The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack | 95.7% | — |
| CVE-2015-0313 | CRIT 9.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil | 95.7% | |
| CVE-2021-34833 | HIGH 7.8 | foxit pdf_reader This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 95.7% | — |
| CVE-2020-5410 | HIGH 7.5 | vmware spring_cloud_config Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a | 95.6% | |
| CVE-2023-21554 | CRIT 9.8 | microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 95.5% | — |
| CVE-2024-21412 | HIGH 8.1 | ransomware microsoft windows_10_1809 Internet Shortcut Files Security Feature Bypass Vulnerability | 95.4% | |
| CVE-2023-49070 | CRIT 9.8 | apache ofbiz Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10 | 95.4% | — |
| CVE-2008-1447 | MED 6.8 | isc bind The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthd | 95.2% | — |
| CVE-2018-0798 | HIGH 8.8 | microsoft office Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". | 95.1% | |
| CVE-2023-36846 | MED 5.3 | juniper junos A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't | 95.1% | |
| CVE-2002-0840 | MED 6.8 | apache http_server Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors | 95.1% | — |
| CVE-2002-0392 | HIGH 7.5 | apache http_server Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size. | 95.0% | — |
| CVE-2017-9798 | HIGH 7.5 | apache http_server Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and | 95.0% | — |
| CVE-2014-6332 | HIGH 8.8 | microsoft windows_7 OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary co | 95.0% | |
| CVE-2024-47575 | CRIT 9.8 | fortinet fortimanager A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiMan | 95.0% | |
| CVE-2006-3918 | MED 4.3 | apache http_server http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an e | 94.9% | — |
| CVE-2024-9474 | HIGH 7.2 | ransomware paloaltonetworks pan-os A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this | 94.7% | |
| CVE-2019-11478 | MED 5.3 | canonical ubuntu_linux Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of servi | 94.7% | — |
| CVE-2023-24941 | CRIT 9.8 | microsoft windows_server_2012 Windows Network File System Remote Code Execution Vulnerability | 94.7% | — |
| CVE-2024-21413 | CRIT 9.8 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 94.7% | |
| CVE-2013-2248 | MED 5.8 | apache struts Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix. | 94.7% | — |
| CVE-2024-31309 | HIGH 7.5 | apache traffic_server HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected. Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minut | 94.6% | — |