57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.620 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22229 | HIGH 8.4 | juniper paragon_active_assurance_control_center An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability, a stored XSS (or persistent), in the Control Center Controller web pages of Juniper Networks Paragon Active Assurance (Formerly Netrounds) allows a high-priv | 0.7% | — |
| CVE-2022-0185 | HIGH 8.4 | linux linux_kernel A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherw | 25.2% | |
| CVE-2021-47456 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: can: peak_pci: peak_pci_remove(): fix UAF When remove the module peek_pci, referencing 'chan' again after releasing 'dev' will cause UAF. Fix this by releasing 'dev' later. The following l | 0.2% | — |
| CVE-2021-47352 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio-net: Add validation for used length This adds validation for used length (might come from an untrusted device) to avoid data corruption or loss. | 0.3% | — |
| CVE-2021-47313 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cpufreq: CPPC: Fix potential memleak in cppc_cpufreq_cpu_init It's a classic example of memleak, we allocate something, we fail and never free the resources. Make sure we free all resources | 0.3% | — |
| CVE-2021-47240 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix OOB Read in qrtr_endpoint_post Syzbot reported slab-out-of-bounds Read in qrtr_endpoint_post. The problem was in wrong _size_ type: if (len != ALIGN(size, 4) + hdrlen) got | 0.2% | — |
| CVE-2021-47049 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Use after free in __vmbus_open() The "open_info" variable is added to the &vmbus_connection.chn_msg_list, but the error handling frees "open_info" without removing it fro | 0.2% | — |
| CVE-2021-43066 | HIGH 8.4 | fortinet forticlient A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below, version 6.2.9 and below, version 6.0.10 and below allows attacker to escalate privilege via the MSI installer. | 0.2% | — |
| CVE-2021-35245 | HIGH 8.4 | solarwinds serv-u When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine. | 1.2% | — |
| CVE-2021-33739 | HIGH 8.4 | microsoft windows_10_1909 Microsoft DWM Core Library Elevation of Privilege Vulnerability | 6.6% | |
| CVE-2021-26864 | HIGH 8.4 | microsoft windows_10 Windows Virtual Registry Provider Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-24105 | HIGH 8.4 | microsoft package_manager_configurations <p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package into a package manager's repository which can be retrieved and used during development, build, and release processes. This insertion could le | 2.1% | — |
| CVE-2021-1051 | HIGH 8.4 | nvidia gpu_driver NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which a local user can get elevated privileges to modify display configuration data, which may result in denial of service of th | 0.3% | — |
| CVE-2021-0066 | HIGH 8.4 | intel amt_ac_8260_firmware Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via local access. | 0.3% | — |
| CVE-2020-8144 | HIGH 8.4 | ui unifi_video The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under certain circumstances, does not validate firmware download destinations to ensure they are within the intended destination directory tree. It ac | 0.7% | — |
| CVE-2020-7861 | HIGH 8.4 | anysupport anysupport AnySupport (Remote support solution) before 2019.3.21.0 allows directory traversing because of swprintf function to copy file from a management PC to a client PC. This can be lead to arbitrary file execution. | 1.5% | — |
| CVE-2020-5945 | HIGH 8.4 | f5 big-ip_access_policy_manager In BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, undisclosed TMUI page contains a stored cross site scripting vulnerability (XSS). The issue allows a minor privilege escalation for resource admin to escalate to full admin. | 1.3% | — |
| CVE-2020-3960 | HIGH 8.4 | vmware fusion VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in NVMe functionality. A malicious actor with local non-administrat | 0.3% | — |
| CVE-2020-3530 | HIGH 8.4 | cisco ios_xr A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to execute that command, even though administrative privileges should be required. The attacker must have valid credential | 0.3% | — |
| CVE-2020-26071 | HIGH 8.4 | cisco catalyst_sd-wan_manager A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to create or overwrite arbitrary files on an affected device, which could result in a denial of service (DoS) condition. The vulnerability is due to insuffic | 0.2% | — |
| CVE-2020-17144 | HIGH 8.4 | microsoft exchange_server Microsoft Exchange Remote Code Execution Vulnerability | 36.5% | |
| CVE-2020-17141 | HIGH 8.4 | microsoft exchange_server Microsoft Exchange Remote Code Execution Vulnerability | 6.6% | — |
| CVE-2020-16875 | HIGH 8.4 | microsoft exchange_server <p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitatio | 47.4% | — |
| CVE-2020-1285 | HIGH 8.4 | microsoft windows_10 <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could th | 4.0% | — |
| CVE-2020-0910 | HIGH 8.4 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. | 9.2% | — |