57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-3752 | HIGH 7.1 | debian debian_linux A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest t | 1.7% | — |
| CVE-2021-3743 | HIGH 7.1 | fedoraproject fedora An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information | 0.7% | — |
| CVE-2021-3739 | HIGH 7.1 | fedoraproject fedora A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. T | 0.6% | — |
| CVE-2021-36949 | HIGH 7.1 | microsoft azure_active_directory_connect Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability | 1.4% | — |
| CVE-2021-35940 | HIGH 7.1 | apache portable_runtime An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 an | 1.2% | — |
| CVE-2021-3506 | HIGH 7.1 | debian debian_linux An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a lea | 0.4% | — |
| CVE-2021-3501 | HIGH 7.1 | fedoraproject fedora A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this v | 0.4% | — |
| CVE-2021-34468 | HIGH 7.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2021-34467 | HIGH 7.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 6.6% | — |
| CVE-2021-32078 | HIGH 7.1 | linux linux_kernel An Out-of-Bounds Read was discovered in arch/arm/mach-footbridge/personal-pci.c in the Linux kernel through 5.12.11 because of the lack of a check for a value that shouldn't be negative, e.g., access to element -2 of an array, aka CID-298a58e165e4. | 0.6% | — |
| CVE-2021-31963 | HIGH 7.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2021-31360 | HIGH 7.1 | juniper junos An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) allows a low-privileged user to overwrite local files as root, possibly leading to a system integrity issue or Denial of Service | 0.2% | — |
| CVE-2021-31354 | HIGH 7.1 | juniper junos An Out Of Bounds (OOB) access vulnerability in the handling of responses by a Juniper Agile License (JAL) Client in Juniper Networks Junos OS and Junos OS Evolved, configured in Network Mode (to use Juniper Agile License Manager) may allow an attacker to cause | 0.6% | — |
| CVE-2021-31182 | HIGH 7.1 | microsoft windows_10 Microsoft Bluetooth Driver Spoofing Vulnerability | 0.8% | — |
| CVE-2021-31172 | HIGH 7.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1.8% | — |
| CVE-2021-29964 | HIGH 7.1 | mozilla firefox A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thun | 0.8% | — |
| CVE-2021-28452 | HIGH 7.1 | microsoft 365_apps Microsoft Outlook Memory Corruption Vulnerability | 1.3% | — |
| CVE-2021-28446 | HIGH 7.1 | microsoft windows_10 Windows Portmapping Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-27364 | HIGH 7.1 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages. | 1.0% | — |
| CVE-2021-26866 | HIGH 7.1 | microsoft windows_10 Windows Update Service Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-26619 | HIGH 7.1 | bigfile bigfileagent An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent. Remote attackers can use this vulnerability to delete arbitrary files of unspecified number of users. | 0.9% | — |
| CVE-2021-26618 | HIGH 7.1 | tmax tooffice An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers use this vulnerability to execute arbitrary file included malicious code. | 1.0% | — |
| CVE-2021-26420 | HIGH 7.1 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 3.0% | — |
| CVE-2021-26088 | HIGH 7.1 | fortinet fortinet_single_sign-on An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets. | 1.0% | — |
| CVE-2021-22128 | HIGH 7.1 | fortinet fortiproxy An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connection functi | 1.0% | — |