IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2021-43217 HIGH 8.1 microsoft windows_10 Windows Encrypting File System (EFS) Remote Code Execution Vulnerability 6.4% —
CVE-2021-43216 MED 6.5 microsoft windows_10 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability 3.2% —
CVE-2021-43215 CRIT 9.8 microsoft windows_10 iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution 2.7% —
CVE-2021-43214 HIGH 7.8 microsoft raw_image_extension Web Media Extensions Remote Code Execution Vulnerability 1.7% —
CVE-2021-43211 MED 5.5 microsoft windows_10_update_assistant Windows 10 Update Assistant Elevation of Privilege Vulnerability 0.9% —
CVE-2021-43209 HIGH 7.8 microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability 6.8% —
CVE-2021-43208 HIGH 7.8 microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability 4.3% —
CVE-2021-43207 HIGH 7.8 microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability 0.6% —
CVE-2021-43206 MED 4.3 fortinet fortios A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.0.x allows malicious webservers to retrieve a web proxy's client username and IP 0.8% —
CVE-2021-43205 MED 4.3 fortinet forticlient An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external 0.9% —
CVE-2021-43204 MED 4.4 fortinet forticlient A improper control of a resource through its lifetime in Fortinet FortiClientWindows version 6.4.1 and 6.4.0, version 6.2.9 and below, version 6.0.10 and below allows attacker to cause a complete denial of service of its components via changes of directory acc 0.3% —
CVE-2021-43083 HIGH 8.8 apache plc4x Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a u 1.9% —
CVE-2021-43082 CRIT 9.8 apache traffic_server Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0. 2.4% —
CVE-2021-43081 MED 6.1 fortinet fortios An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may 0.9% —
CVE-2021-43080 MED 4.6 fortinet fortios An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack t 0.4% —
CVE-2021-43077 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or comma 0.8% —
CVE-2021-43076 MED 6.3 fortinet fortiadc An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 and below, 5.4.5 and below and 5.3.7 and below may allow a remote authenticated attacker with restricted user profile to modify the system fil 0.5% —
CVE-2021-43075 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or 1.6% —
CVE-2021-43074 MED 4.3 fortinet fortios An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all versions; Fort 0.3% —
CVE-2021-43073 HIGH 8.8 fortinet fortiweb A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HT 1.4% —
CVE-2021-43072 MED 6.7 fortinet fortianalyzer A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6.11 and below, FortiManager version 7.0.2 and bel 0.2% —
CVE-2021-43071 HIGH 8.8 fortinet fortiweb A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the LogReport API controller. 1.2% —
CVE-2021-43070 MED 5.4 fortinet fortiwlm Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem 0.6% —
CVE-2021-43068 MED 5.4 fortinet fortiauthenticator A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal. 0.6% —
CVE-2021-43067 HIGH 8.3 fortinet fortiauthenticator A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and below, version 6.1.2 and below, version 6.0.7 to 6.0.1 allows attacker to duplicate a target LDAP user 2 facto 1.1% —