57.061 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.061 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-38659 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 6.3% | — |
| CVE-2021-38658 | HIGH 7.8 | microsoft office Microsoft Office Graphics Remote Code Execution Vulnerability | 6.3% | — |
| CVE-2021-38656 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 6.7% | — |
| CVE-2021-38655 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 6.3% | — |
| CVE-2021-38654 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 6.3% | — |
| CVE-2021-38653 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 6.3% | — |
| CVE-2021-38648 | HIGH 7.8 | microsoft azure_automation_state_configuration Open Management Infrastructure Elevation of Privilege Vulnerability | 11.4% | |
| CVE-2021-38646 | HIGH 7.8 | ransomware microsoft 365_apps Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | 8.0% | |
| CVE-2021-38645 | HIGH 7.8 | microsoft azure_automation_state_configuration Open Management Infrastructure Elevation of Privilege Vulnerability | 2.7% | |
| CVE-2021-38644 | HIGH 7.8 | microsoft mpeg-2_video_extension Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-38639 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2021-38638 | HIGH 7.8 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38633 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-38630 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38628 | HIGH 7.8 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38626 | HIGH 7.8 | microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38625 | HIGH 7.8 | microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38571 | HIGH 7.8 | foxitsoftware foxit_reader An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502. | 0.5% | — |
| CVE-2021-3847 | HIGH 7.8 | fedoraproject fedora An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate thei | 0.5% | — |
| CVE-2021-38300 | HIGH 7.8 | debian debian_linux arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel context. This occurs because conditional branches can exceed th | 0.6% | — |
| CVE-2021-38166 | HIGH 7.8 | debian debian_linux In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability. | 0.3% | — |
| CVE-2021-38160 | HIGH 7.8 | debian debian_linux In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vul | 0.4% | — |
| CVE-2021-38088 | HIGH 7.8 | acronis cyber_protect Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking. | 0.2% | — |
| CVE-2021-38086 | HIGH 7.8 | acronis cyber_protect Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking. | 0.3% | — |
| CVE-2021-37969 | HIGH 7.8 | debian debian_linux Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file. | 0.9% | — |