56.950 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.950 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-3059 | CRIT 9.8 | adobe flash_player Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the internal script object. Successful exploitation could lead to arbitrary code execution. | 9.5% | — |
| CVE-2017-3037 | CRIT 9.8 | adobe acrobat Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the JavaScript engine. Successful exploitation could lead to arbitrary code execution. | 6.3% | — |
| CVE-2017-3010 | CRIT 9.8 | adobe acrobat Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the rendering engine. Successful exploitation could lead to arbitrary code execution. | 4.6% | — |
| CVE-2017-2345 | CRIT 9.8 | juniper junos On Junos OS devices with SNMP enabled, a network based attacker with unfiltered access to the RE can cause the Junos OS snmpd daemon to crash and restart by sending a crafted SNMP packet. Repeated crashes of the snmpd daemon can result in a partial denial of s | 3.6% | — |
| CVE-2017-20005 | CRIT 9.8 | debian debian_linux NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module. | 3.3% | — |
| CVE-2017-18379 | CRIT 9.8 | linux linux_kernel In the Linux kernel before 4.14, an out of boundary access happened in drivers/nvme/target/fc.c. | 2.8% | — |
| CVE-2017-18269 | CRIT 9.8 | gnu glibc An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not correctly perform the overlapping memory check if the source memory range spans the mi | 4.2% | — |
| CVE-2017-18174 | CRIT 9.8 | linux linux_kernel In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a double free. | 3.3% | — |
| CVE-2017-18017 | CRIT 9.8 | arista eos The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by le | 52.8% | — |
| CVE-2017-17836 | CRIT 9.8 | apache airflow In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow, whether it be via XSS or by leaving a machine unlocked can e | 3.3% | — |
| CVE-2017-17671 | CRIT 9.8 | vbulletin vbulletin vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can include directory traversal sequences to specify an arbitrary pathname, and because ../ traversal is blocked b | 3.0% | — |
| CVE-2017-17540 | CRIT 9.8 | fortinet fortiwlc The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell. | 1.8% | — |
| CVE-2017-17539 | CRIT 9.8 | fortinet fortiwlc The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shell. | 1.8% | — |
| CVE-2017-15944 | CRIT 9.8 | paloaltonetworks pan-os Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface. | 98.3% | |
| CVE-2017-15940 | CRIT 9.8 | paloaltonetworks pan-os The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors. | 4.9% | — |
| CVE-2017-15718 | CRIT 9.8 | apache hadoop The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications. | 3.6% | — |
| CVE-2017-15714 | CRIT 9.8 | apache ofbiz The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the URL an alert window | 3.3% | — |
| CVE-2017-15708 | CRIT 9.8 | apache synapse In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecti | 17.7% | — |
| CVE-2017-15702 | CRIT 9.8 | apache qpid_broker-j In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can be tricked by a remote unauthenticated attacker connecting to the HTTP port into | 6.2% | — |
| CVE-2017-15697 | CRIT 9.8 | apache nifi A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix to properly handle these headers was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x rele | 4.8% | — |
| CVE-2017-15692 | CRIT 9.8 | apache geode In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cause remote code execution if certain classes are present on the | 4.8% | — |
| CVE-2017-14491 | CRIT 9.8 | arista eos Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | 84.9% | — |
| CVE-2017-14397 | CRIT 9.8 | anydesk anydesk AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability. | 1.5% | — |
| CVE-2017-14189 | CRIT 9.8 | fortinet fortiweb_manager An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password. | 2.8% | — |
| CVE-2017-13715 | CRIT 9.8 | linux linux_kernel The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are initialized, which allows remote attackers to cause a denial of service (system crash) or possibly execute arbitra | 9.7% | — |