57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-36962 | MED 5.5 | microsoft windows_10 Windows Installer Information Disclosure Vulnerability | 1.3% | — |
| CVE-2021-36961 | MED 5.5 | microsoft windows_10 Windows Installer Denial of Service Vulnerability | 1.1% | — |
| CVE-2021-36959 | MED 5.5 | microsoft windows_10 Windows Authenticode Spoofing Vulnerability | 1.3% | — |
| CVE-2021-36938 | MED 5.5 | microsoft windows_10 Windows Cryptographic Primitives Library Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-3679 | MED 5.5 | debian debian_linux A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve | 0.7% | — |
| CVE-2021-3669 | MED 5.5 | debian debian_linux A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS. | 0.3% | — |
| CVE-2021-3659 | MED 5.5 | fedoraproject fedora A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to s | 0.3% | — |
| CVE-2021-36374 | MED 5.5 | apache ant When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly u | 2.6% | — |
| CVE-2021-36373 | MED 5.5 | apache ant When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.1 | 2.5% | — |
| CVE-2021-36190 | MED 5.5 | fortinet fortiweb A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to access protected hosts via crafted HTTP requests. | 0.8% | — |
| CVE-2021-36151 | MED 5.5 | apache gobblin In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems. This affects versions <= 0.15.0. Users should update to version 0.16.0 which addresses this issue. | 0.4% | — |
| CVE-2021-36077 | MED 5.5 | adobe bridge Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SVG file, potentially resulting in local application denial of service in the context of the current user. User interaction is requ | 1.7% | — |
| CVE-2021-36060 | MED 5.5 | adobe media_encoder Adobe Media Encoder version 15.2 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue re | 0.3% | — |
| CVE-2021-36003 | MED 5.5 | adobe audition Adobe Audition version 14.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the cur | 1.9% | — |
| CVE-2021-3564 | MED 5.5 | debian debian_linux A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versi | 0.5% | — |
| CVE-2021-35477 | MED 5.5 | debian debian_linux In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not necessarily occur before a store operat | 0.5% | — |
| CVE-2021-34976 | MED 5.5 | foxit pdf_editor Foxit PDF Reader PDF File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vuln | 0.3% | — |
| CVE-2021-34973 | MED 5.5 | foxit pdf_editor Foxit PDF Reader PDF File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vuln | 0.3% | — |
| CVE-2021-34972 | MED 5.5 | foxit pdf_editor Foxit PDF Reader AcroForm Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerabilit | 0.3% | — |
| CVE-2021-34970 | MED 5.5 | foxit pdf_editor Foxit PDF Reader print Method Use of Externally-Controlled Format String Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is requi | 0.3% | — |
| CVE-2021-34969 | MED 5.5 | foxit pdf_editor Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerabil | 0.3% | — |
| CVE-2021-34949 | MED 5.5 | foxit pdf_editor Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulner | 0.3% | — |
| CVE-2021-34771 | MED 5.5 | cisco ios_xr A vulnerability in the Cisco IOS XR Software CLI could allow an authenticated, local attacker to view more information than their privileges allow. This vulnerability is due to insufficient application of restrictions during the execution of a specific command | 0.3% | — |
| CVE-2021-34733 | MED 5.5 | cisco evolved_programmable_network_manager A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file system of an affected system. This vulnerab | 0.2% | — |
| CVE-2021-34711 | MED 5.5 | cisco ip_conference_phone_7832_firmware A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any file on the device file system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by p | 0.3% | — |