58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22040 | HIGH 7.3 | microsoft windows_10 Internet Information Services Dynamic Compression Module Denial of Service Vulnerability | 1.5% | — |
| CVE-2022-20739 | HIGH 7.3 | cisco catalyst_sd-wan_manager A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected system as a low-privi | 0.6% | — |
| CVE-2022-0883 | HIGH 7.3 | snowsoftware snow_license_manager SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched. | 0.2% | — |
| CVE-2021-47441 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mlxsw: thermal: Fix out-of-bounds memory accesses Currently, mlxsw allows cooling states to be set above the maximum cooling state supported by the driver: # cat /sys/class/thermal/thermal | 0.2% | — |
| CVE-2021-46912 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: Make tcp_allowed_congestion_control readonly in non-init netns Currently, tcp_allowed_congestion_control is global and writable; writing to it in any net namespace will leak into all ot | 0.2% | — |
| CVE-2021-44466 | HIGH 7.3 | leap bitmask_riseup_vpn Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software is installed with a non-default installation directory off of the system root, the installer fails to properly set ACLs. This allows lower p | 0.4% | — |
| CVE-2021-44226 | HIGH 7.3 | razer synapse Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have pla | 0.9% | — |
| CVE-2021-44206 | HIGH 7.3 | acronis cyber_protect_home_office Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder service. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287 | 0.2% | — |
| CVE-2021-44205 | HIGH 7.3 | acronis cyber_protect_home_office Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287 | 0.2% | — |
| CVE-2021-42955 | HIGH 7.3 | zohocorp manageengine_remote_access_plus Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the password of the Remote Acce | 0.4% | — |
| CVE-2021-42923 | HIGH 7.3 | showmypc showmypc ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability. If an attacker overwrites the file %temp%\ShowMyPC\-ShowMyPC3606\wodVPN.dll, it will run any malicious code contained in that file. The code will run with normal user privileges unless the user | 0.2% | — |
| CVE-2021-41027 | HIGH 7.3 | fortinet fortiweb A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute unauthorized code or commands via crafted certificates loaded into the device. | 0.2% | — |
| CVE-2021-41025 | HIGH 7.3 | fortinet fortiweb Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurrent execution using shared resource with i | 1.4% | — |
| CVE-2021-40708 | HIGH 7.3 | adobe genuine_service Adobe Genuine Service versions 7.3 (and earlier) are affected by a privilege escalation vulnerability in the AGSService installer. An authenticated attacker could leverage this vulnerability to achieve read / write privileges to execute arbitrary code. User in | 1.7% | — |
| CVE-2021-38295 | HIGH 7.3 | apache couchdb In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code em | 2.5% | — |
| CVE-2021-36945 | HIGH 7.3 | microsoft windows_10_update_assistant Windows 10 Update Assistant Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2021-35982 | HIGH 7.3 | adobe acrobat_dc Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Uncontrolled Search Path Element vulnerability. A local attacker with non-administrative privileges can plant a malicious | 1.8% | — |
| CVE-2021-33766 | HIGH 7.3 | microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability | 98.1% | |
| CVE-2021-33436 | HIGH 7.3 | nomachine nomachine NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system | 0.3% | — |
| CVE-2021-31949 | HIGH 7.3 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2021-31938 | HIGH 7.3 | microsoft kubernetes_tools Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2021-31519 | HIGH 7.3 | trendmicro housecall_for_home_networks An incorrect permission vulnerability in the product installer folders for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be e | 0.3% | — |
| CVE-2021-31204 | HIGH 7.3 | fedoraproject fedora .NET and Visual Studio Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2021-28649 | HIGH 7.3 | trendmicro housecall_for_home_networks An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed | 0.3% | — |
| CVE-2021-28581 | HIGH 7.3 | adobe creative_cloud Adobe Creative Cloud Desktop 3.5 (and earlier) is affected by an uncontrolled search path vulnerability that could result in elevation of privileges. Exploitation of this issue requires user interaction in that a victim must log on to the attacker's local mach | 0.9% | — |