57.921 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.921 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-1015 | MED 6.6 | fedoraproject fedora A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows a local user to cause an out-of-bounds write issue. | 1.5% | — |
| CVE-2021-47230 | MED 6.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Immediately reset the MMU context when the SMM flag is cleared Immediately reset the MMU context when the vCPU's SMM flag is cleared so that the SMM flag in the MMU role is always | 0.2% | — |
| CVE-2021-44832 | MED 6.6 | apache log4j Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of | 97.9% | — |
| CVE-2021-42304 | MED 6.6 | microsoft azure_real_time_operating_system Azure RTOS Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-42303 | MED 6.6 | microsoft azure_real_time_operating_system Azure RTOS Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-42302 | MED 6.6 | microsoft azure_real_time_operating_system Azure RTOS Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-31207 | MED 6.6 | ransomware microsoft exchange_server Microsoft Exchange Server Security Feature Bypass Vulnerability | 99.8% | |
| CVE-2021-26854 | MED 6.6 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 23.0% | — |
| CVE-2021-23338 | MED 6.6 | microsoft qlib This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function. | 3.6% | — |
| CVE-2021-22600 | MED 6.6 | debian debian_linux A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a | 6.1% | |
| CVE-2021-21057 | MED 6.6 | adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a null pointer dereference vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker coul | 1.1% | — |
| CVE-2021-1646 | MED 6.6 | microsoft windows_10 Windows WLAN Service Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1492 | MED 6.6 | duo authentication_proxy The Duo Authentication Proxy installer prior to 5.2.1 did not properly validate file installation paths. This allows an attacker with local user privileges to coerce the installer to write to arbitrary privileged directories. If successful, an attacker can man | 0.3% | — |
| CVE-2021-1485 | MED 6.6 | cisco ios_xr A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges on the underlying Linux operating system (OS) of an affected device. This vulnerability is due | 0.3% | — |
| CVE-2021-1371 | MED 6.6 | cisco ios_xe_sd-wan A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when the device is in the default SD-WAN confi | 0.3% | — |
| CVE-2020-36695 | MED 6.6 | hitachi compute_systems_manager Incorrect Default Permissions vulnerability in Hitachi Device Manager on Linux (Device Manager Server component), Hitachi Tiered Storage Manager on Linux, Hitachi Replication Manager on Linux, Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hit | 0.2% | — |
| CVE-2020-36652 | MED 6.6 | hitachi automation_director Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infrastructure Analytics Advisor, Analytics probe server components), Hitachi Ops Center Automator on Linux, Hitachi | 0.1% | — |
| CVE-2020-36611 | MED 6.6 | hitachi tuning_manager Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAID, Hitachi Tuning Manager - Agent for NAS, Hitachi Tuning Manager - Agent for SAN Switch components) allows loc | 0.1% | — |
| CVE-2020-36605 | MED 6.6 | hitachi infrastructure_analytics_advisor Incorrect Default Permissions vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Analyzer probe component), Hitachi Ops Center Viewpoint on Linux (Viewpoint RAID Agent component | 0.2% | — |
| CVE-2020-3427 | MED 6.6 | cisco duo_authentication_for_windows_logon_and_rdp The Windows Logon installer prior to 4.1.2 did not properly validate file installation paths. This allows an attacker with local user privileges to coerce the installer to write to arbitrary privileged directories. If successful, an attacker can manipulate fil | 0.3% | — |
| CVE-2020-17117 | MED 6.6 | microsoft exchange_server Microsoft Exchange Remote Code Execution Vulnerability | 48.9% | — |
| CVE-2020-17049 | MED 6.6 | microsoft windows_server_2012 A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD). To exploit the vulnerability, a compromised service that is configured | 13.7% | — |
| CVE-2020-1666 | MED 6.6 | juniper junos_os_evolved The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the console cable is disconnected. This could allow a malicious attacker with physical access to the console the ab | 0.3% | — |
| CVE-2020-1590 | MED 6.6 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system.</p> < | 0.8% | — |
| CVE-2020-14331 | MED 6.6 | linux linux_kernel A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur. This flaw allows a local user with ac | 0.6% | — |