57.061 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.061 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-3760 | HIGH 7.8 | debian debian_linux A flaw was found in the Linux kernel. A use-after-free vulnerability in the NFC stack can lead to a threat to confidentiality, integrity, and system availability. | 0.4% | — |
| CVE-2021-37576 | HIGH 7.8 | fedoraproject fedora arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e. | 0.6% | — |
| CVE-2021-3715 | HIGH 7.8 | linux linux_kernel A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escal | 0.4% | — |
| CVE-2021-36975 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2021-36974 | HIGH 7.8 | microsoft windows_10 Windows SMB Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36973 | HIGH 7.8 | microsoft windows_10 Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36968 | HIGH 7.8 | microsoft windows_7 Windows DNS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36966 | HIGH 7.8 | microsoft windows_10 Windows Subsystem for Linux Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36964 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36963 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-36958 | HIGH 7.8 | microsoft windows A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the | 30.6% | — |
| CVE-2021-36957 | HIGH 7.8 | microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36955 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 4.0% | |
| CVE-2021-36952 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 51.2% | — |
| CVE-2021-36948 | HIGH 7.8 | microsoft windows_10_1809 Windows Update Medic Service Elevation of Privilege Vulnerability | 26.7% | |
| CVE-2021-36941 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-36937 | HIGH 7.8 | microsoft windows_10 Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-36934 | HIGH 7.8 | microsoft windows_10_1809 An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitr | 67.3% | |
| CVE-2021-36927 | HIGH 7.8 | microsoft windows_7 Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36744 | HIGH 7.8 | trendmicro maximum_security_2019 Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the system to escalate privileges and create a denial of service. | 0.5% | — |
| CVE-2021-36742 | HIGH 7.8 | trendmicro apex_one A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obta | 1.5% | |
| CVE-2021-36376 | HIGH 7.8 | delta_project delta dandavison delta before 0.8.3 on Windows resolves an executable's pathname as a relative path from the current directory. | 0.4% | — |
| CVE-2021-3612 | HIGH 7.8 | debian debian_linux An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on t | 0.7% | — |
| CVE-2021-36089 | HIGH 7.8 | zope grok Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::applyColour). | 1.2% | — |
| CVE-2021-36081 | HIGH 7.8 | tesseract_ocr_project tesseract_ocr Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call. | 0.9% | — |