58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1064 | HIGH 7.1 | nvidia virtual_gpu_manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which it obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer, which may lead to information disclosure or denial of service. This | 0.3% | — |
| CVE-2021-1062 | HIGH 7.1 | nvidia virtual_gpu_manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3). | 0.3% | — |
| CVE-2021-1060 | HIGH 7.1 | nvidia virtual_gpu_manager NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input index is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (pr | 0.3% | — |
| CVE-2021-1058 | HIGH 7.1 | nvidia virtual_gpu_manager NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input data size is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 | 0.3% | — |
| CVE-2021-1056 | HIGH 7.1 | debian debian_linux NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of s | 1.8% | — |
| CVE-2021-0226 | HIGH 7.1 | juniper junos_os_evolved On Juniper Networks Junos OS Evolved devices, receipt of a specific IPv6 packet may cause an established IPv6 BGP session to terminate, creating a Denial of Service (DoS) condition. Continued receipt and processing of this packet will create a sustained Denial | 0.9% | — |
| CVE-2020-9383 | HIGH 7.1 | canonical ubuntu_linux An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2. | 0.8% | — |
| CVE-2020-8648 | HIGH 7.1 | broadcom brocade_fabric_operating_system_firmware There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c. | 0.7% | — |
| CVE-2020-8428 | HIGH 7.1 | linux linux_kernel fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9. One attack vector may be an ope | 0.7% | — |
| CVE-2020-5912 | HIGH 7.1 | f5 big-ip_access_policy_manager In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the restjavad process's dump command does not follow current best coding practices and may overwrite arbitrary files. | 0.3% | — |
| CVE-2020-5880 | HIGH 7.1 | f5 big-ip_access_policy_manager Om BIG-IP 15.0.0-15.0.1.3 and 14.1.0-14.1.2.3, the restjavad process may expose a way for attackers to upload arbitrary files on the BIG-IP system, bypassing the authorization system. Resulting error messages may also reveal internal paths of the server. | 1.3% | — |
| CVE-2020-4411 | HIGH 7.1 | ibm spectrum_scale The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service vulnerability in its kernel module that could allow an attacker to cause a denial of service condition on the affected system. To e | 0.3% | — |
| CVE-2020-3991 | HIGH 7.1 | vmware horizon_client VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-service vulnerability due to a file system access control issue during install time. Successful exploitation of this issue may allow an attacker to overwrite certain admin privileged fil | 0.3% | — |
| CVE-2020-36386 | HIGH 7.1 | linux linux_kernel An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci_extended_inquiry_result_evt, aka CID-51c19bf3d5cf. | 0.5% | — |
| CVE-2020-3483 | HIGH 7.1 | cisco duo_network_gateway Duo has identified and fixed an issue with the Duo Network Gateway (DNG) product in which some customer-provided SSL certificates and private keys were not excluded from logging. This issue resulted in certificate and private key information being written out | 0.1% | — |
| CVE-2020-3267 | HIGH 7.1 | cisco unified_contact_center_express A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an aff | 0.8% | — |
| CVE-2020-3264 | HIGH 7.1 | cisco sd-wan_firmware A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending | 0.7% | — |
| CVE-2020-3148 | HIGH 7.1 | cisco prime_network_registrar A vulnerability in the web-based interface of Cisco Prime Network Registrar (CPNR) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protec | 0.5% | — |
| CVE-2020-29075 | HIGH 7.1 | adobe acrobat Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opene | 7.9% | — |
| CVE-2020-24558 | HIGH 7.1 | trendmicro apex_one A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services dll may allow an attacker to manipulate it to cause an out-of-bounds read that crashes multiple processes in the product. An attacker mu | 0.6% | — |
| CVE-2020-24394 | HIGH 7.1 | canonical ubuntu_linux In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered. | 0.4% | — |
| CVE-2020-23922 | HIGH 7.1 | apache bookkeeper An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read. | 2.2% | — |
| CVE-2020-2005 | HIGH 7.1 | paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalProtect Clientless VPN that can compromise the user's active session. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 v | 0.9% | — |
| CVE-2020-17089 | HIGH 7.1 | microsoft sharepoint_foundation Microsoft SharePoint Elevation of Privilege Vulnerability | 2.9% | — |
| CVE-2020-16969 | HIGH 7.1 | microsoft exchange_server <p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user.</p> <p>To exploit the | 2.7% | — |