58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-14208 | HIGH 7.5 | foxitsoftware phantompdf An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a NULL pointer dereference and crash when getting a PDF object from a document, or parsing a certain portfolio that contains a null dictionary. | 1.6% | — |
| CVE-2019-13400 | CRIT 9.8 | fortinet fcm-mb40_firmware Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retrieved via cgi-bin/getuserinfo.cgi?mode=info. | 1.6% | — |
| CVE-2017-8720 | HIGH 7.8 | microsoft windows_10 The Microsoft Windows graphics component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privile | 1.6% | — |
| CVE-2023-35088 | CRIT 9.8 | apache inlong Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. In the toAuditCkSql method, the groupId, streamId, audit | 1.6% | — |
| CVE-2022-33637 | MED 6.5 | microsoft defender_for_endpoint Microsoft Defender for Endpoint Tampering Vulnerability | 1.6% | — |
| CVE-2019-11839 | CRIT 9.8 | f5 njs njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to njs_array_prototype_push in njs/njs_array.c, because of njs_array_expand size mishandling. | 1.6% | — |
| CVE-2016-1333 | MED 6.5 | cisco ios Cisco IOS 15.5(3)M and 15.6(1)T0a on Cisco 1000 Connected Grid routers allows remote authenticated users to cause a denial of service (device reload) via an SNMP request for unspecified BRIDGE MIB OIDs, aka Bug ID CSCux89878. | 1.6% | — |
| CVE-2015-6366 | MED 5.0 | cisco ios Cisco IOS 15.2(04)M6 and 15.4(03)S lets physical-interface ACLs supersede tunnel-interface ACLs, which allows remote attackers to bypass intended network-traffic restrictions in opportunistic circumstances by using a tunnel, aka Bug ID CSCur01042. | 1.6% | — |
| CVE-2002-1555 | MED 5.0 | cisco optical_networking_systems_software Cisco ONS15454 and ONS15327 running ONS before 3.4 uses a "public" SNMP community string that cannot be changed, which allows remote attackers to obtain sensitive information. | 1.6% | — |
| CVE-2020-4200 | MED 6.5 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated attacker to send specially crafted commands to cause a denial of service. IBM X-Force ID: 174914. | 1.6% | — |
| CVE-2020-16994 | HIGH 7.3 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.6% | — |
| CVE-2017-7682 | HIGH 8.2 | apache openmeetings Apache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted areas. | 1.6% | — |
| CVE-2015-0012 | MED 6.9 | microsoft virtual_machine_manager Microsoft System Center Virtual Machine Manager (VMM) 2012 R2 Update Rollup 4 does not properly validate the roles of users, which allows local users to obtain server and virtual-machine administrative privileges by establishing a server session with Active Di | 1.6% | — |
| CVE-2010-2429 | MED 4.3 | splunk splunk Cross-site scripting (XSS) vulnerability in Splunk 4.0 through 4.1.2, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer in a "404 Not Found" response. | 1.6% | — |
| CVE-2023-27867 | MED 6.3 | ibm db2 IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection. By sending a specially crafted request using the property clientRerouteServerListJNDIName, an | 1.6% | — |
| CVE-2022-41062 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-38040 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-38031 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-37982 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-31673 | HIGH 8.8 | vmware vrealize_operations VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remote code execution. | 1.6% | — |
| CVE-2020-26235 | MED 5.3 | time_project time In Rust time crate from version 0.2.7 and before version 0.2.23, unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires the user to set any environment variable in a different thread than the a | 1.6% | — |
| CVE-2010-3940 | HIGH 7.2 | microsoft windows_2003_server Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted | 1.6% | — |
| CVE-2010-1142 | HIGH 8.5 | vmware ace VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi | 1.6% | — |
| CVE-2007-2999 | LOW 1.8 | microsoft windows_2003_server Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to det | 1.6% | — |
| CVE-2000-0197 | MED 4.6 | microsoft windows_nt The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file. | 1.6% | — |