57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-26708 | HIGH 7.0 | linux linux_kernel A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits that | 1.6% | — |
| CVE-2021-26442 | HIGH 7.0 | microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-26426 | HIGH 7.0 | microsoft windows_10 Windows User Account Profile Picture Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-25329 | HIGH 7.0 | apache tomcat The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE | 9.5% | — |
| CVE-2021-24095 | HIGH 7.0 | microsoft windows_10 DirectX Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-21011 | HIGH 7.0 | adobe captivate Adobe Captivate 2019 version 11.5.1.499 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. An attacker with permissions to write to the file system could leverage this vulnerability to escala | 2.0% | — |
| CVE-2021-21010 | HIGH 7.0 | adobe incopy InCopy version 15.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mus | 2.5% | — |
| CVE-2021-21008 | HIGH 7.0 | adobe animate Adobe Animate version 21.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mali | 2.4% | — |
| CVE-2021-21007 | HIGH 7.0 | adobe illustrator Adobe Illustrator version 25.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a | 2.2% | — |
| CVE-2021-1709 | HIGH 7.0 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1682 | HIGH 7.0 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-1639 | HIGH 7.0 | microsoft visual_studio_2017 Visual Studio Code Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-1567 | HIGH 7.0 | cisco anyconnect_secure_mobility_client A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the An | 0.2% | — |
| CVE-2021-1496 | HIGH 7.0 | cisco anyconnect_secure_mobility_client Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful explo | 0.5% | — |
| CVE-2021-1430 | HIGH 7.0 | cisco anyconnect_secure_mobility_client Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful explo | 0.2% | — |
| CVE-2021-1429 | HIGH 7.0 | cisco anyconnect_secure_mobility_client Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful explo | 0.2% | — |
| CVE-2021-1428 | HIGH 7.0 | cisco anyconnect_secure_mobility_client Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful explo | 0.2% | — |
| CVE-2021-1427 | HIGH 7.0 | cisco anyconnect_secure_mobility_client Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful explo | 0.2% | — |
| CVE-2021-1426 | HIGH 7.0 | cisco anyconnect_secure_mobility_client Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful explo | 0.2% | — |
| CVE-2021-1386 | HIGH 7.0 | cisco advanced_malware_protection_for_endpoints A vulnerability in the dynamic link library (DLL) loading mechanism in Cisco Advanced Malware Protection (AMP) for Endpoints Windows Connector, ClamAV for Windows, and Immunet could allow an authenticated, local attacker to perform a DLL hijacking attack on an | 0.3% | — |
| CVE-2020-9746 | HIGH 7.0 | adobe flash_player Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerability that could result in a crash and arbitrary code execution. Exploitation of this issue requires an attacker to insert malicious strings in | 4.3% | — |
| CVE-2020-9615 | HIGH 7.0 | adobe acrobat_dc Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a race condition vulnerability. Successful exploitation could lead to security feature bypass. | 1.4% | — |
| CVE-2020-9484 | HIGH 7.0 | apache tomcat When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager | 56.6% | — |
| CVE-2020-7816 | HIGH 7.0 | hmtalk daoffice A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticated, remote attacker to cause an arbitrary code execution on an affected device.nThe vulnerability is due to a stack overflow read. An attacke | 1.4% | — |
| CVE-2020-3957 | HIGH 7.0 | vmware fusion VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Suc | 0.2% | — |