57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-24107 | MED 5.5 | microsoft windows_10 Windows Event Tracing Information Disclosure Vulnerability | 1.0% | — |
| CVE-2021-24106 | MED 5.5 | microsoft windows_10 Windows DirectX Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-24098 | MED 5.5 | microsoft windows_10 Windows Console Driver Denial of Service Vulnerability | 1.5% | — |
| CVE-2021-24084 | MED 5.5 | microsoft windows_10 Windows Mobile Device Management Information Disclosure Vulnerability | 2.8% | — |
| CVE-2021-24079 | MED 5.5 | microsoft windows_10 Windows Backup Engine Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-24076 | MED 5.5 | microsoft windows_10 Microsoft Windows VMSwitch Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-23827 | MED 5.5 | keybase keybase Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, ev | 0.3% | — |
| CVE-2021-23021 | MED 5.5 | f5 nginx_controller The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to 644. | 0.2% | — |
| CVE-2021-23020 | MED 5.5 | f5 nginx_controller The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys. | 0.3% | — |
| CVE-2021-22020 | MED 5.5 | vmware cloud_foundation The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server. | 0.2% | — |
| CVE-2021-22007 | MED 5.5 | vmware cloud_foundation The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue to gain access to sensitive information. | 0.2% | — |
| CVE-2021-21997 | MED 5.5 | vmware tools VMware Tools for Windows (11.x.y prior to 11.3.0) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest operating system, where VMware Tools is installed, can trigger a PANIC in the V | 0.7% | — |
| CVE-2021-21292 | MED 5.5 | traccar traccar Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path vulnerability. Only Windows versions are impacted. Attacker needs write access to the filesystem on the host machine. If Java path includes a | 0.4% | — |
| CVE-2021-21096 | MED 5.5 | adobe bridge Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Improper Authorization vulnerability in the Genuine Software Service. A low-privileged attacker could leverage this vulnerability to achieve application denial-of-service in | 0.7% | — |
| CVE-2021-20490 | MED 5.5 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X-Force ID: 197791. | 0.2% | — |
| CVE-2021-20408 | MED 5.5 | ibm security_verify_information_queue IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaintext cryptographic key. IBM X-Force ID: 198187. | 0.2% | — |
| CVE-2021-20320 | MED 5.5 | fedoraproject fedora A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem. | 0.3% | — |
| CVE-2021-20265 | MED 5.5 | linux linux_kernel A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from t | 0.3% | — |
| CVE-2021-20219 | MED 5.5 | linux linux_kernel A denial of service vulnerability was found in n_tty_receive_char_special in drivers/tty/n_tty.c of the Linux kernel. In this flaw a local attacker with a normal user privilege could delay the loop (due to a changing ldata->read_head, and a missing sanity chec | 0.4% | — |
| CVE-2021-1731 | MED 5.5 | microsoft windows_10 PFX Encryption Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2021-1725 | MED 5.5 | microsoft bot_framework_software_development_kit Bot Framework SDK Information Disclosure Vulnerability | 1.1% | — |
| CVE-2021-1699 | MED 5.5 | microsoft windows_10 Windows (modem.sys) Information Disclosure Vulnerability | 2.1% | — |
| CVE-2021-1696 | MED 5.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 4.4% | — |
| CVE-2021-1677 | MED 5.5 | microsoft azure_kubernetes_service Azure Active Directory Pod Identity Spoofing Vulnerability | 1.1% | — |
| CVE-2021-1676 | MED 5.5 | microsoft windows_10 Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability | 1.3% | — |