IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-38649 HIGH 7.0 microsoft azure_automation_state_configuration Open Management Infrastructure Elevation of Privilege Vulnerability 2.9%
CVE-2021-3864 HIGH 7.0 debian debian_linux A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then ha 0.8%
CVE-2021-3640 HIGH 7.0 canonical ubuntu_linux A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expec 0.4%
CVE-2021-3609 HIGH 7.0 linux linux_kernel .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows f 0.4%
CVE-2021-34788 HIGH 7.0 cisco anyconnect_secure_mobility_client A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS could allow an authenticated, local attacker to perform a shared library hijacking attack on an affected device if the VPN Posture (HostScan 0.2%
CVE-2021-34487 HIGH 7.0 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.6%
CVE-2021-34462 HIGH 7.0 microsoft windows_10 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability 0.9%
CVE-2021-34449 HIGH 7.0 microsoft windows_10 Win32k Elevation of Privilege Vulnerability 2.7%
CVE-2021-33774 HIGH 7.0 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.6%
CVE-2021-33762 HIGH 7.0 microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability 0.6%
CVE-2021-33751 HIGH 7.0 microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability 0.8%
CVE-2021-3348 HIGH 7.0 debian debian_linux nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-after-free that could be triggered by local attackers (with access to the nbd device) via an I/O request at a certain point during device setup, aka CID-b98e762e3 0.3%
CVE-2021-32466 HIGH 7.0 trendmicro housecall_for_home_networks An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malic 0.5%
CVE-2021-32399 HIGH 7.0 debian debian_linux net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller. 0.7%
CVE-2021-31440 HIGH 7.0 linux linux_kernel This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specif 1.8%
CVE-2021-29645 HIGH 7.0 hitachi it_operations_director Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the l 0.2%
CVE-2021-29221 HIGH 7.0 erlang erlang\/otp A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3. By adding files to an existing installation's directory, a local attacker could hijack accounts of other users running Erlang programs or possibly coerce a service 0.6%
CVE-2021-28477 HIGH 7.0 microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability 2.3%
CVE-2021-28440 HIGH 7.0 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 0.6%
CVE-2021-27893 HIGH 7.0 ssh tectia_client SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. ConnectSecure on Windows is affected. 0.4%
CVE-2021-27072 HIGH 7.0 microsoft windows_10 Win32k Elevation of Privilege Vulnerability 0.6%
CVE-2021-27055 HIGH 7.0 microsoft 365_apps Microsoft Visio Security Feature Bypass Vulnerability 2.5%
CVE-2021-26873 HIGH 7.0 microsoft windows_10 Windows User Profile Service Elevation of Privilege Vulnerability 1.1%
CVE-2021-26863 HIGH 7.0 microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability 11.8%
CVE-2021-26862 HIGH 7.0 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 1.2%