57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-47503 | MED 6.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Do not call scsi_remove_host() in pm8001_alloc() Calling scsi_remove_host() before scsi_add_host() results in a crash: BUG: kernel NULL pointer dereference, address: 00000000 | 0.2% | — |
| CVE-2021-47375 | MED 6.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: blktrace: Fix uaf in blk_trace access after removing by sysfs There is an use-after-free problem triggered by following process: P1(sda) P2(sdb) echo 0 > /sys/block/sdb/trace/en | 0.3% | — |
| CVE-2021-47329 | MED 6.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Fix resource leak in case of probe failure The driver doesn't clean up all the allocated resources properly when scsi_add_host(), megasas_start_aen() function fails durin | 0.3% | — |
| CVE-2021-47228 | MED 6.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: x86/ioremap: Map EFI-reserved memory as encrypted for SEV Some drivers require memory that is marked as EFI boot services data. In order for this memory to not be re-used by the kernel after | 0.2% | — |
| CVE-2021-47147 | MED 6.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: Fix a resource leak in an error handling path If an error occurs after a successful 'pci_ioremap_bar()' call, it must be undone by a corresponding 'pci_iounmap()' call, as already | 0.2% | — |
| CVE-2021-33765 | MED 6.2 | microsoft windows_10 Windows Installer Spoofing Vulnerability | 0.7% | — |
| CVE-2021-30002 | MED 6.2 | debian debian_linux An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory leak for large arguments, aka CID-fb18802a338b. | 0.4% | — |
| CVE-2021-27074 | MED 6.2 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.2% | — |
| CVE-2021-26892 | MED 6.2 | microsoft windows_10 Windows Extensible Firmware Interface Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2021-26413 | MED 6.2 | microsoft windows_10 Windows Installer Spoofing Vulnerability | 0.7% | — |
| CVE-2021-26113 | MED 6.2 | fortinet fortiwan A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker who has previously come in possession of the password file to potentially guess passwords therein stored. | 0.4% | — |
| CVE-2021-21055 | MED 6.2 | adobe dreamweaver Adobe Dreamweaver versions 21.0 (and earlier) and 20.2 (and earlier) is affected by an untrusted search path vulnerability that could result in information disclosure. An attacker with physical access to the system could replace certain configuration files and | 0.8% | — |
| CVE-2021-20536 | MED 6.2 | ibm spectrum_protect_plus IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836. | 0.3% | — |
| CVE-2021-1537 | MED 6.2 | cisco thousandeyes_recorder A vulnerability in the installer software of Cisco ThousandEyes Recorder could allow an unauthenticated, local attacker to access sensitive information that is contained in the ThousandEyes Recorder installer software. This vulnerability exists because sensiti | 0.2% | — |
| CVE-2020-7811 | MED 6.2 | samsung update Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker are executed while the engine deserializes the data received during inter-process communication | 0.7% | — |
| CVE-2020-17085 | MED 6.2 | microsoft exchange_server Microsoft Exchange Server Denial of Service Vulnerability | 3.6% | — |
| CVE-2020-16990 | MED 6.2 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 1.5% | — |
| CVE-2020-16986 | MED 6.2 | microsoft azure_sphere Azure Sphere Denial of Service Vulnerability | 1.3% | — |
| CVE-2020-16985 | MED 6.2 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 1.7% | — |
| CVE-2020-16910 | MED 6.2 | microsoft windows_10 <p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.</p> <p>To exploit this vulne | 2.8% | — |
| CVE-2019-3016 | MED 6.2 | linux linux_kernel In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a guest running linux kernel 4.16 or later | 0.6% | — |
| CVE-2019-25567 | MED 6.2 | valentina-db studio Valentina Studio 9.0.5 Linux contains a buffer overflow vulnerability in the Host field of the connection dialog that allows local attackers to crash the application by supplying an oversized input string. Attackers can trigger the vulnerability by pasting a c | 0.2% | — |
| CVE-2019-14284 | MED 6.2 | linux linux_kernel In the Linux kernel before 5.2.3, drivers/block/floppy.c allows a denial of service by setup_format_params division-by-zero. Two consecutive ioctls can trigger the bug: the first one should set the drive geometry with .sect and .rate values that make F_SECT_PE | 0.7% | — |
| CVE-2019-1399 | MED 6.2 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-071 | 1.7% | — |
| CVE-2019-0928 | MED 6.2 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. | 1.7% | — |