58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-1247 | HIGH 7.0 | fedoraproject fedora An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh->use to represent how many objects are using the rose_neigh. When a user wants to delete a rose_route via rose_ioctl(), the rose driver calls rose_ | 0.3% | — |
| CVE-2022-1048 | HIGH 7.0 | debian debian_linux A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or | 0.2% | — |
| CVE-2022-0017 | HIGH 7.0 | paloaltonetworks globalprotect An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that enables a local attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privilege | 0.3% | — |
| CVE-2021-47479 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8712: fix use-after-free in rtl8712_dl_fw Syzbot reported use-after-free in rtl8712_dl_fw(). The problem was in race condition between r871xu_dev_remove() ->ndo_open() callback. | 0.2% | — |
| CVE-2021-47280 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm: Fix use-after-free read in drm_getunique() There is a time-of-check-to-time-of-use error in drm_getunique() due to retrieving file_priv->master prior to locking the device's master mute | 0.2% | — |
| CVE-2021-47088 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm/damon/dbgfs: protect targets destructions with kdamond_lock DAMON debugfs interface iterates current monitoring targets in 'dbgfs_target_ids_read()' while holding the corresponding 'kdamo | 0.2% | — |
| CVE-2021-46910 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ARM: 9063/1: mm: reduce maximum number of CPUs if DEBUG_KMAP_LOCAL is enabled The debugging code for kmap_local() doubles the number of per-CPU fixmap slots allocated for kmap_local(), in or | 0.2% | — |
| CVE-2021-44733 | HIGH 7.0 | debian debian_linux A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object. | 0.7% | — |
| CVE-2021-42835 | HIGH 7.0 | plex media_server An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the atta | 1.2% | — |
| CVE-2021-4202 | HIGH 7.0 | linux linux_kernel A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed, leading to | 0.4% | — |
| CVE-2021-41334 | HIGH 7.0 | microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2021-4083 | HIGH 7.0 | debian debian_linux A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash t | 0.3% | — |
| CVE-2021-40490 | HIGH 7.0 | debian debian_linux A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13. | 0.3% | — |
| CVE-2021-38649 | HIGH 7.0 | microsoft azure_automation_state_configuration Open Management Infrastructure Elevation of Privilege Vulnerability | 2.9% | |
| CVE-2021-3864 | HIGH 7.0 | debian debian_linux A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then ha | 0.8% | — |
| CVE-2021-3640 | HIGH 7.0 | canonical ubuntu_linux A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expec | 0.4% | — |
| CVE-2021-3609 | HIGH 7.0 | linux linux_kernel .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows f | 0.4% | — |
| CVE-2021-34788 | HIGH 7.0 | cisco anyconnect_secure_mobility_client A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS could allow an authenticated, local attacker to perform a shared library hijacking attack on an affected device if the VPN Posture (HostScan | 0.2% | — |
| CVE-2021-34487 | HIGH 7.0 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-34462 | HIGH 7.0 | microsoft windows_10 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-34449 | HIGH 7.0 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2021-33774 | HIGH 7.0 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-33762 | HIGH 7.0 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-33751 | HIGH 7.0 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-3348 | HIGH 7.0 | debian debian_linux nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-after-free that could be triggered by local attackers (with access to the nbd device) via an I/O request at a certain point during device setup, aka CID-b98e762e3 | 0.3% | — |