IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2021-42295 MED 5.5 microsoft 365_apps Visual Basic for Applications Information Disclosure Vulnerability 2.9% —
CVE-2021-42294 HIGH 7.2 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 2.2% —
CVE-2021-42293 MED 6.5 microsoft 365_apps Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability 2.8% —
CVE-2021-42291 HIGH 7.5 microsoft windows_server Active Directory Domain Services Elevation of Privilege Vulnerability 4.2% —
CVE-2021-42288 MED 5.7 microsoft windows_10 Windows Hello Security Feature Bypass Vulnerability 0.7% —
CVE-2021-42286 HIGH 7.8 microsoft windows_10 Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability 0.5% —
CVE-2021-42285 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.5% —
CVE-2021-42284 MED 6.8 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 3.7% —
CVE-2021-42283 HIGH 8.8 microsoft windows_10 NTFS Elevation of Privilege Vulnerability 0.5% —
CVE-2021-42282 HIGH 7.5 microsoft windows_server Active Directory Domain Services Elevation of Privilege Vulnerability 4.2% —
CVE-2021-42280 MED 5.5 microsoft windows_10 Windows Feedback Hub Elevation of Privilege Vulnerability 0.9% —
CVE-2021-42279 MED 4.2 microsoft windows_10 Chakra Scripting Engine Memory Corruption Vulnerability 2.3% —
CVE-2021-42277 MED 5.5 microsoft visual_studio Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability 0.9% —
CVE-2021-42276 HIGH 7.8 microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 2.5% —
CVE-2021-42275 HIGH 8.8 microsoft windows_10 Microsoft COM for Windows Remote Code Execution Vulnerability 2.1% —
CVE-2021-42274 MED 6.8 microsoft windows_10 Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability 0.7% —
CVE-2021-42272 HIGH 7.8 adobe animate Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a 2.7% —
CVE-2021-42265 MED 5.5 adobe premiere_pro Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exp 0.3% —
CVE-2021-42264 MED 5.5 adobe premiere_pro Adobe Premiere Pro 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of t 1.1% —
CVE-2021-42263 MED 5.5 adobe premiere_pro Adobe Premiere Pro 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of t 1.1% —
CVE-2021-42252 HIGH 7.8 linux linux_kernel An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, 0.4% —
CVE-2021-42250 MED 6.5 apache superset Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs. 1.8% —
CVE-2021-4225 HIGH 8.8 smartypantsplugins sp_project_\&_document_manager The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking 1.7% —
CVE-2021-4218 MED 5.5 linux linux_kernel A flaw was found in the Linux kernel’s implementation of reading the SVC RDMA counters. Reading the counter sysctl panics the system. This flaw allows a local attacker with local access to cause a denial of service while the system reboots. The issue is specif 0.3% —
CVE-2021-42108 HIGH 7.8 trendmicro apex_one Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first 0.4% —