57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-39849 | MED 5.5 | adobe acrobat Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an applica | 1.9% | — |
| CVE-2021-39048 | MED 5.5 | ibm spectrum_protect_backup-archive_client IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438. | 0.3% | — |
| CVE-2021-39032 | MED 5.5 | ibm sterling_gentran IBM Sterling Gentran:Server for Microsoft Windows 5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 213962. | 0.3% | — |
| CVE-2021-38976 | MED 5.5 | ibm security_guardium_key_lifecycle_manager IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: 212781. | 0.2% | — |
| CVE-2021-38959 | MED 5.5 | ibm spss_statistics IBM SPSS Statistics for Windows 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 could allow a local user to cause a denial of service by writing arbitrary files to admin protected directories on the system. IBM X-Force ID: 212046. | 0.2% | — |
| CVE-2021-38949 | MED 5.5 | ibm mq IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 211403. | 0.2% | — |
| CVE-2021-38926 | MED 5.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210321. | 0.3% | — |
| CVE-2021-38663 | MED 5.5 | microsoft windows_10 Windows exFAT File System Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-38662 | MED 5.5 | microsoft windows_10 Windows Fast FAT File System Driver Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-38637 | MED 5.5 | microsoft windows_10 Windows Storage Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-38636 | MED 5.5 | microsoft windows_10 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-38635 | MED 5.5 | microsoft windows_10 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-3848 | MED 5.5 | trendmicro apex_one An arbitrary file creation by privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1, and Worry-Free Business Security Services could allow a local attacker to create an arbitrary file with high | 0.2% | — |
| CVE-2021-38208 | MED 5.5 | linux linux_kernel net/nfc/llcp_sock.c in the Linux kernel before 5.12.10 allows local unprivileged users to cause a denial of service (NULL pointer dereference and BUG) by making a getsockname call after a certain type of failure of a bind call. | 0.5% | — |
| CVE-2021-38206 | MED 5.5 | linux linux_kernel The mac80211 subsystem in the Linux kernel before 5.12.13, when a device supporting only 5 GHz is used, allows attackers to cause a denial of service (NULL pointer dereference in the radiotap parser) by injecting a frame with 802.11a rates. | 0.3% | — |
| CVE-2021-38203 | MED 5.5 | linux linux_kernel btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info. | 0.4% | — |
| CVE-2021-38200 | MED 5.5 | linux linux_kernel arch/powerpc/perf/core-book3s.c in the Linux kernel before 5.12.13, on systems with perf_event_paranoid=-1 and no specific PMU driver support registered, allows local users to cause a denial of service (perf_instruction_pointer NULL pointer dereference and OOP | 0.3% | — |
| CVE-2021-38198 | MED 5.5 | debian debian_linux arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page, leading to a missing guest protection page fault. | 0.5% | — |
| CVE-2021-3764 | MED 5.5 | linux linux_kernel A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The vulnerability is similar to the older CVE-2019-18808. The highest threat from this vulnerability is to system availabili | 0.3% | — |
| CVE-2021-3759 | MED 5.5 | debian debian_linux A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial o | 0.4% | — |
| CVE-2021-3744 | MED 5.5 | debian debian_linux A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is similar with the older CVE-2019-18808. | 0.5% | — |
| CVE-2021-3736 | MED 5.5 | linux linux_kernel A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O (VFIO) Mediated devices. This flaw could allow a local attacker to leak internal kernel information. | 0.2% | — |
| CVE-2021-3732 | MED 5.5 | linux linux_kernel A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not be accessible. | 0.3% | — |
| CVE-2021-36972 | MED 5.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-36969 | MED 5.5 | microsoft windows_10 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability | 0.9% | — |