IT
58.306 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-21292 MED 5.5 traccar traccar Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path vulnerability. Only Windows versions are impacted. Attacker needs write access to the filesystem on the host machine. If Java path includes a 0.4% —
CVE-2021-21096 MED 5.5 adobe bridge Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Improper Authorization vulnerability in the Genuine Software Service. A low-privileged attacker could leverage this vulnerability to achieve application denial-of-service in 0.7% —
CVE-2021-20490 MED 5.5 ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X-Force ID: 197791. 0.2% —
CVE-2021-20408 MED 5.5 ibm security_verify_information_queue IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaintext cryptographic key. IBM X-Force ID: 198187. 0.2% —
CVE-2021-20320 MED 5.5 fedoraproject fedora A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem. 0.3% —
CVE-2021-20265 MED 5.5 linux linux_kernel A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from t 0.3% —
CVE-2021-20219 MED 5.5 linux linux_kernel A denial of service vulnerability was found in n_tty_receive_char_special in drivers/tty/n_tty.c of the Linux kernel. In this flaw a local attacker with a normal user privilege could delay the loop (due to a changing ldata->read_head, and a missing sanity chec 0.4% —
CVE-2021-1731 MED 5.5 microsoft windows_10 PFX Encryption Security Feature Bypass Vulnerability 0.9% —
CVE-2021-1725 MED 5.5 microsoft bot_framework_software_development_kit Bot Framework SDK Information Disclosure Vulnerability 1.1% —
CVE-2021-1699 MED 5.5 microsoft windows_10 Windows (modem.sys) Information Disclosure Vulnerability 2.1% —
CVE-2021-1696 MED 5.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 4.4% —
CVE-2021-1677 MED 5.5 microsoft azure_kubernetes_service Azure Active Directory Pod Identity Spoofing Vulnerability 1.1% —
CVE-2021-1676 MED 5.5 microsoft windows_10 Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability 1.3% —
CVE-2021-1672 MED 5.5 microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability 1.3% —
CVE-2021-1670 MED 5.5 microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability 1.2% —
CVE-2021-1663 MED 5.5 microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability 1.2% —
CVE-2021-1656 MED 5.5 microsoft windows_10 TPM Device Driver Information Disclosure Vulnerability 3.0% —
CVE-2021-1637 MED 5.5 microsoft windows_10 Windows DNS Query Information Disclosure Vulnerability 1.2% —
CVE-2021-1612 MED 5.5 cisco sd-wan A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files on the local system. This vulnerability is due to improper access controls on files within the local file system. An attacker coul 0.3% —
CVE-2021-1568 MED 5.5 cisco anyconnect_secure_mobility_client A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to uncontrolled memory allocation. An attacker cou 0.2% —
CVE-2021-1546 MED 5.5 cisco catalyst_sd-wan_manager A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information. This vulnerability is due to improper protections on file access through the CLI. An attacker could exploit this vulnerability by 0.2% —
CVE-2021-1544 MED 5.5 cisco webex_meetings A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authenticated, local attacker to gain access to sensitive information. This vulnerability is due to unsafe logging of application actions. An attacker could exploit th 0.2% —
CVE-2021-1450 MED 5.5 cisco anyconnect_secure_mobility_client A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. To exploit this vulnerability, the attac 0.2% —
CVE-2021-1443 MED 5.5 cisco ios_xe A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system of an affected device. The vulnerability exists because the affected software 2.3% —
CVE-2021-1438 MED 5.5 cisco wide_area_application_services A vulnerability in Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper input validation and authorization of speci 0.2% —