58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2021-20322 | HIGH 7.4 | debian debian_linux A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source | 6.8% | — |
| CVE-2021-20321 | MED 4.7 | debian debian_linux A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS. A local user could use this flaw to crash the system. | 0.2% | — |
| CVE-2021-20320 | MED 5.5 | fedoraproject fedora A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem. | 0.3% | — |
| CVE-2021-20317 | MED 4.4 | debian debian_linux A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and event | 0.4% | — |
| CVE-2021-20292 | MED 6.7 | debian debian_linux There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouveau_sgdma_create_ttm in Nouveau DRM subsystem. The issue results from the lack of validating the existence of an object prior to performing op | 0.9% | — |
| CVE-2021-20268 | HIGH 7.8 | linux linux_kernel An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user running the eBPF script calls dev_map_init_map or sock_map_alloc. This flaw allows a local user to crash the system or possibly escalate the | 0.3% | — |
| CVE-2021-20265 | MED 5.5 | linux linux_kernel A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from t | 0.3% | — |
| CVE-2021-20261 | MED 6.4 | linux linux_kernel A race condition was found in the Linux kernels implementation of the floppy disk drive controller driver software. The impact of this issue is lessened by the fact that the default permissions on the floppy device (/dev/fd0) are restricted to root. If the per | 0.2% | — |
| CVE-2021-20239 | LOW 3.3 | fedoraproject fedora A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vulnerability is to confidentiality. | 0.3% | — |
| CVE-2021-20226 | HIGH 7.8 | linux linux_kernel A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial of service problem on the system The issue results from the lack of validating the existence of an object prior to performing ope | 0.4% | — |
| CVE-2021-20219 | MED 5.5 | linux linux_kernel A denial of service vulnerability was found in n_tty_receive_char_special in drivers/tty/n_tty.c of the Linux kernel. In this flaw a local attacker with a normal user privilege could delay the loop (due to a changing ldata->read_head, and a missing sanity chec | 0.4% | — |
| CVE-2021-20194 | HIGH 7.8 | linux linux_kernel There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is register | 0.4% | — |
| CVE-2021-20190 | HIGH 8.1 | apache nifi A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | 7.5% | — |
| CVE-2021-2018 | HIGH 8.3 | oracle adaptive_access_manager Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advan | 1.4% | — |
| CVE-2021-20177 | MED 4.4 | linux linux_kernel A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root or CAP_NET_ADMIN) when inserting iptables rules could insert a rule which can panic the system. Kernel before kernel 5.5-rc1 is affected. | 0.3% | — |
| CVE-2021-20100 | MED 6.7 | tenable nessus Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE-2021 | 0.5% | — |
| CVE-2021-20099 | MED 6.7 | tenable nessus Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE-2021 | 0.4% | — |
| CVE-2021-20081 | HIGH 7.2 | zohocorp manageengine_servicedesk_plus Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges. | 52.4% | — |
| CVE-2021-1734 | HIGH 7.5 | microsoft windows_10 Windows Remote Procedure Call Information Disclosure Vulnerability | 3.8% | — |
| CVE-2021-1733 | HIGH 7.8 | microsoft psexec Sysinternals PsExec Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-1731 | MED 5.5 | microsoft windows_10 PFX Encryption Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2021-1730 | MED 5.4 | microsoft exchange_server <p>A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor to impersonate the user.</p> <p>This update addresses this vulnerability.</p> <p>To prevent these types of attacks, Microsoft rec | 1.8% | — |
| CVE-2021-1729 | HIGH 7.1 | microsoft windows_10 Windows Update Stack Setup Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-1728 | HIGH 8.8 | microsoft system_center_operations_manager System Center Operations Manager Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2021-1727 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.8% | — |