58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-27070 | HIGH 7.3 | microsoft windows_10 Windows 10 Update Assistant Elevation of Privilege Vulnerability | 3.9% | — |
| CVE-2021-26093 | HIGH 7.3 | fortinet fortiwlc An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash the access point being managed by the controller by executing a crafted CLI command. | 0.2% | — |
| CVE-2021-1706 | HIGH 7.3 | microsoft windows_10 Windows LUAFV Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2021-1704 | HIGH 7.3 | microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-1685 | HIGH 7.3 | microsoft windows_10 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-1593 | HIGH 7.3 | cisco packet_tracer A vulnerability in Cisco Packet Tracer for Windows could allow an authenticated, local attacker to perform a DLL injection attack on an affected device. To exploit this vulnerability, the attacker must have valid credentials on the Windows system. This vulnera | 0.3% | — |
| CVE-2021-1432 | HIGH 7.3 | cisco ios_xe A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected device as a low-privil | 0.3% | — |
| CVE-2021-1085 | HIGH 7.3 | nvidia virtual_gpu_manager NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to write to a shared memory location and manipulate the data after the data has been validated, which may lead to denial of service and escalatio | 0.2% | — |
| CVE-2021-0260 | HIGH 7.3 | juniper junos An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) service of Juniper Networks Junos OS leads an unauthenticated attacker being able to perform SNMP read actions, an Exposure of System Data to an Unauthorized Contr | 0.9% | — |
| CVE-2021-0246 | HIGH 7.3 | juniper junos On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, devices using tenant services on Juniper Networks Junos OS, due to incorrect default permissions assigned to tenant system administrators a tenant system administrator may inadvertently send | 0.2% | — |
| CVE-2021-0235 | HIGH 7.3 | juniper junos On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, vSRX Series devices using tenant services on Juniper Networks Junos OS, due to incorrect permission scheme assigned to tenant system administrators, a tenant system administrator may inadver | 0.2% | — |
| CVE-2020-5911 | HIGH 7.3 | f5 nginx_controller In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system. | 1.0% | — |
| CVE-2020-4265 | HIGH 7.3 | ibm i2_analysts_notebook IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbi | 0.4% | — |
| CVE-2020-3588 | HIGH 7.3 | cisco webex_meetings A vulnerability in virtualization channel messaging in Cisco Webex Meetings Desktop App for Windows could allow a local attacker to execute arbitrary code on a targeted system. This vulnerability occurs when this app is deployed in a virtual desktop environmen | 0.4% | — |
| CVE-2020-3556 | HIGH 7.3 | cisco anyconnect_secure_mobility_client A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious script. The vulnerability is due to a la | 0.4% | — |
| CVE-2020-35452 | HIGH 7.3 | apache http_server Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler | 54.8% | — |
| CVE-2020-3405 | HIGH 7.3 | cisco sd-wan_firmware A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity | 1.3% | — |
| CVE-2020-3376 | HIGH 7.3 | cisco data_center_network_manager A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions on an affected device. The vulnerability is due to a failure in | 1.2% | — |
| CVE-2020-3240 | HIGH 7.3 | cisco ucs_director Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne | 38.7% | — |
| CVE-2020-26233 | HIGH 7.3 | microsoft git_credential_manager_core Git Credential Manager Core (GCM Core) is a secure Git credential helper built on .NET Core that runs on Windows and macOS. In Git Credential Manager Core before version 2.0.289, when recursively cloning a Git repository on Windows with submodules, Git will fi | 6.0% | — |
| CVE-2020-16994 | HIGH 7.3 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.6% | — |
| CVE-2020-16991 | HIGH 7.3 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.7% | — |
| CVE-2020-16987 | HIGH 7.3 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.3% | — |
| CVE-2020-16984 | HIGH 7.3 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.3% | — |
| CVE-2020-1571 | HIGH 7.3 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Setup in the way it handles permissions. A locally authenticated attacker could run arbitrary code with elevated system privileges. After successfully exploiting the vulnerability, an attacker could the | 1.1% | — |