57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-22127 | HIGH 7.1 | fortinet forticlient An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x before 6.2.9 may allow an unauthenticated attacker to execute arbitrary code on the host operating system as root via tricking the user into con | 0.5% | — |
| CVE-2021-21315 | HIGH 7.1 | apache cordova The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerabilit | 90.7% | |
| CVE-2021-21076 | HIGH 7.1 | adobe animate Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requir | 3.2% | — |
| CVE-2021-21075 | HIGH 7.1 | adobe animate Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requir | 3.0% | — |
| CVE-2021-21074 | HIGH 7.1 | adobe animate Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requir | 3.2% | — |
| CVE-2021-21072 | HIGH 7.1 | adobe animate Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requir | 3.0% | — |
| CVE-2021-1729 | HIGH 7.1 | microsoft windows_10 Windows Update Stack Setup Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-1365 | HIGH 7.1 | cisco unified_communications_manager_im_and_presence_service Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilities are due | 1.1% | — |
| CVE-2021-1363 | HIGH 7.1 | cisco unified_communications_manager_im_and_presence_service Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilities are due | 1.1% | — |
| CVE-2021-1086 | HIGH 7.1 | nvidia virtual_gpu_manager NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it allows guests to control unauthorized resources, which may lead to integrity and confidentiality loss or information disclosure. This affects vGPU version 12.x (prior | 0.2% | — |
| CVE-2021-1065 | HIGH 7.1 | nvidia virtual_gpu_manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3). | 0.3% | — |
| CVE-2021-1064 | HIGH 7.1 | nvidia virtual_gpu_manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which it obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer, which may lead to information disclosure or denial of service. This | 0.3% | — |
| CVE-2021-1062 | HIGH 7.1 | nvidia virtual_gpu_manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3). | 0.3% | — |
| CVE-2021-1060 | HIGH 7.1 | nvidia virtual_gpu_manager NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input index is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (pr | 0.3% | — |
| CVE-2021-1058 | HIGH 7.1 | nvidia virtual_gpu_manager NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input data size is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 | 0.3% | — |
| CVE-2021-1056 | HIGH 7.1 | debian debian_linux NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of s | 1.8% | — |
| CVE-2021-0226 | HIGH 7.1 | juniper junos_os_evolved On Juniper Networks Junos OS Evolved devices, receipt of a specific IPv6 packet may cause an established IPv6 BGP session to terminate, creating a Denial of Service (DoS) condition. Continued receipt and processing of this packet will create a sustained Denial | 0.9% | — |
| CVE-2020-9383 | HIGH 7.1 | canonical ubuntu_linux An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2. | 0.7% | — |
| CVE-2020-8648 | HIGH 7.1 | broadcom brocade_fabric_operating_system_firmware There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c. | 0.7% | — |
| CVE-2020-8428 | HIGH 7.1 | linux linux_kernel fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9. One attack vector may be an ope | 0.7% | — |
| CVE-2020-5912 | HIGH 7.1 | f5 big-ip_access_policy_manager In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the restjavad process's dump command does not follow current best coding practices and may overwrite arbitrary files. | 0.3% | — |
| CVE-2020-5880 | HIGH 7.1 | f5 big-ip_access_policy_manager Om BIG-IP 15.0.0-15.0.1.3 and 14.1.0-14.1.2.3, the restjavad process may expose a way for attackers to upload arbitrary files on the BIG-IP system, bypassing the authorization system. Resulting error messages may also reveal internal paths of the server. | 1.3% | — |
| CVE-2020-4411 | HIGH 7.1 | ibm spectrum_scale The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service vulnerability in its kernel module that could allow an attacker to cause a denial of service condition on the affected system. To e | 0.3% | — |
| CVE-2020-3991 | HIGH 7.1 | vmware horizon_client VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-service vulnerability due to a file system access control issue during install time. Successful exploitation of this issue may allow an attacker to overwrite certain admin privileged fil | 0.3% | — |
| CVE-2020-36386 | HIGH 7.1 | linux linux_kernel An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci_extended_inquiry_result_evt, aka CID-51c19bf3d5cf. | 0.5% | — |