IT
57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.620 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-22229 HIGH 8.4 juniper paragon_active_assurance_control_center An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability, a stored XSS (or persistent), in the Control Center Controller web pages of Juniper Networks Paragon Active Assurance (Formerly Netrounds) allows a high-priv 0.7%
CVE-2022-0185 HIGH 8.4 linux linux_kernel A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherw 25.2%
CVE-2021-47456 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: can: peak_pci: peak_pci_remove(): fix UAF When remove the module peek_pci, referencing 'chan' again after releasing 'dev' will cause UAF. Fix this by releasing 'dev' later. The following l 0.2%
CVE-2021-47352 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio-net: Add validation for used length This adds validation for used length (might come from an untrusted device) to avoid data corruption or loss. 0.3%
CVE-2021-47313 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cpufreq: CPPC: Fix potential memleak in cppc_cpufreq_cpu_init It's a classic example of memleak, we allocate something, we fail and never free the resources. Make sure we free all resources 0.3%
CVE-2021-47240 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix OOB Read in qrtr_endpoint_post Syzbot reported slab-out-of-bounds Read in qrtr_endpoint_post. The problem was in wrong _size_ type: if (len != ALIGN(size, 4) + hdrlen) got 0.2%
CVE-2021-47049 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Use after free in __vmbus_open() The "open_info" variable is added to the &vmbus_connection.chn_msg_list, but the error handling frees "open_info" without removing it fro 0.2%
CVE-2021-43066 HIGH 8.4 fortinet forticlient A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below, version 6.2.9 and below, version 6.0.10 and below allows attacker to escalate privilege via the MSI installer. 0.2%
CVE-2021-35245 HIGH 8.4 solarwinds serv-u When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine. 1.2%
CVE-2021-33739 HIGH 8.4 microsoft windows_10_1909 Microsoft DWM Core Library Elevation of Privilege Vulnerability 6.6%
CVE-2021-26864 HIGH 8.4 microsoft windows_10 Windows Virtual Registry Provider Elevation of Privilege Vulnerability 0.7%
CVE-2021-24105 HIGH 8.4 microsoft package_manager_configurations <p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package into a package manager's repository which can be retrieved and used during development, build, and release processes. This insertion could le 2.1%
CVE-2021-1051 HIGH 8.4 nvidia gpu_driver NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which a local user can get elevated privileges to modify display configuration data, which may result in denial of service of th 0.3%
CVE-2021-0066 HIGH 8.4 intel amt_ac_8260_firmware Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via local access. 0.3%
CVE-2020-8144 HIGH 8.4 ui unifi_video The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under certain circumstances, does not validate firmware download destinations to ensure they are within the intended destination directory tree. It ac 0.7%
CVE-2020-7861 HIGH 8.4 anysupport anysupport AnySupport (Remote support solution) before 2019.3.21.0 allows directory traversing because of swprintf function to copy file from a management PC to a client PC. This can be lead to arbitrary file execution. 1.5%
CVE-2020-5945 HIGH 8.4 f5 big-ip_access_policy_manager In BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, undisclosed TMUI page contains a stored cross site scripting vulnerability (XSS). The issue allows a minor privilege escalation for resource admin to escalate to full admin. 1.3%
CVE-2020-3960 HIGH 8.4 vmware fusion VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in NVMe functionality. A malicious actor with local non-administrat 0.3%
CVE-2020-3530 HIGH 8.4 cisco ios_xr A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to execute that command, even though administrative privileges should be required. The attacker must have valid credential 0.3%
CVE-2020-26071 HIGH 8.4 cisco catalyst_sd-wan_manager A vulnerability in the CLI of Cisco&nbsp;SD-WAN Software could allow an authenticated, local attacker to create or overwrite arbitrary files on an affected device, which could result in a denial of service (DoS) condition. The vulnerability is due to insuffic 0.2%
CVE-2020-17144 HIGH 8.4 microsoft exchange_server Microsoft Exchange Remote Code Execution Vulnerability 36.5%
CVE-2020-17141 HIGH 8.4 microsoft exchange_server Microsoft Exchange Remote Code Execution Vulnerability 6.6%
CVE-2020-16875 HIGH 8.4 microsoft exchange_server <p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitatio 47.4%
CVE-2020-1285 HIGH 8.4 microsoft windows_10 <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could th 4.0%
CVE-2020-0910 HIGH 8.4 microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. 9.2%