58.306 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-29648 | MED 5.5 | fedoraproject fedora An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_ids and resolved_sizes are intentionally uninitialized in the vmlinux BPF Type Format (BTF), which can cause a system crash upon an unexpecte | 0.3% | — |
| CVE-2021-29647 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID-50535249f624. | 0.4% | — |
| CVE-2021-29646 | MED 5.5 | fedoraproject fedora An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c does not properly validate certain data sizes, aka CID-0217ed2848e8. | 0.3% | — |
| CVE-2021-29264 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel through 5.11.10. drivers/net/ethernet/freescale/gianfar.c in the Freescale Gianfar Ethernet driver allows attackers to cause a system crash because a negative fragment size is calculated in situations involving an rx | 0.3% | — |
| CVE-2021-29155 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel | 1.1% | — |
| CVE-2021-28971 | MED 5.5 | debian debian_linux In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b | 0.4% | — |
| CVE-2021-28951 | MED 5.5 | fedoraproject fedora An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (deadlock) because exit may be waiting to park a SQPOLL thread, but concurrently that SQPOLL thread is waiting for a signal to start, | 0.3% | — |
| CVE-2021-28950 | MED 5.5 | debian debian_linux An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1. | 0.4% | — |
| CVE-2021-28657 | MED 5.5 | apache tika A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later. | 2.8% | — |
| CVE-2021-28623 | MED 5.5 | adobe premiere_elements Adobe Premiere Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privileged actions. Exploi | 0.5% | — |
| CVE-2021-28619 | MED 5.5 | adobe animate Adobe Animate version 21.0.6 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the cu | 3.2% | — |
| CVE-2021-28618 | MED 5.5 | adobe animate Adobe Animate version 21.0.6 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the cu | 3.3% | — |
| CVE-2021-28617 | MED 5.5 | adobe animate Adobe Animate version 21.0.6 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the cu | 3.3% | — |
| CVE-2021-28615 | MED 5.5 | adobe after_effects Adobe After Effects version 18.2 (and earlier) is affected by an Our-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of th | 2.4% | — |
| CVE-2021-28609 | MED 5.5 | adobe after_effects Adobe After Effects version 18.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of th | 2.5% | — |
| CVE-2021-28600 | MED 5.5 | adobe after_effects Adobe After Effects version 18.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of th | 2.4% | — |
| CVE-2021-28597 | MED 5.5 | adobe photoshop_elements Adobe Photoshop Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privileged actions. Explo | 0.5% | — |
| CVE-2021-28479 | MED 5.5 | microsoft windows_10 Windows CSC Service Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28456 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 3.7% | — |
| CVE-2021-28443 | MED 5.5 | microsoft windows_10 Windows Console Driver Denial of Service Vulnerability | 0.6% | — |
| CVE-2021-28438 | MED 5.5 | microsoft windows_10 Windows Console Driver Denial of Service Vulnerability | 0.7% | — |
| CVE-2021-28437 | MED 5.5 | microsoft windows_10 Windows Installer Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28435 | MED 5.5 | microsoft windows_10 Windows Event Tracing Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28326 | MED 5.5 | microsoft windows_10 Windows AppX Deployment Server Denial of Service Vulnerability | 1.0% | — |
| CVE-2021-28318 | MED 5.5 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 0.8% | — |