58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2021-41374 | MED 6.7 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-41373 | MED 5.5 | microsoft fslogix FSLogix Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-41372 | HIGH 7.6 | microsoft power_bi_report_server A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulne | 0.7% | — |
| CVE-2021-41371 | MED 4.4 | microsoft windows_10 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | 1.6% | — |
| CVE-2021-41370 | HIGH 7.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41368 | MED 6.1 | microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability | 4.9% | — |
| CVE-2021-41367 | HIGH 7.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41366 | HIGH 7.8 | microsoft windows_10 Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41365 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-41363 | MED 4.2 | microsoft intune_management_extension Intune Management Extension Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2021-41361 | MED 5.4 | microsoft windows_server_2016 Active Directory Federation Server Spoofing Vulnerability | 0.9% | — |
| CVE-2021-41360 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2021-41356 | HIGH 7.5 | microsoft windows_10 Windows Denial of Service Vulnerability | 3.0% | — |
| CVE-2021-41355 | MED 5.7 | microsoft .net .NET Core and Visual Studio Information Disclosure Vulnerability | 20.3% | — |
| CVE-2021-41354 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2021-41353 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability | 0.9% | — |
| CVE-2021-41352 | HIGH 7.5 | microsoft system_center_operations_manager SCOM Information Disclosure Vulnerability | 2.9% | — |
| CVE-2021-41351 | MED 4.3 | microsoft edge Microsoft Edge (Chrome based) Spoofing on IE Mode | 3.9% | — |
| CVE-2021-41350 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 1.9% | — |
| CVE-2021-4135 | MED 5.5 | linux linux_kernel A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way user uses BPF for the device such that function nsim_map_alloc_elem being called. A local user could use this flaw to get unauthorized access | 0.2% | — |
| CVE-2021-41349 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 93.5% | — |
| CVE-2021-41348 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-41347 | HIGH 7.8 | microsoft windows_10 Windows AppX Deployment Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-41346 | MED 5.3 | microsoft windows_10 Console Window Host Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2021-41345 | HIGH 7.8 | microsoft windows_10 Storage Spaces Controller Elevation of Privilege Vulnerability | 0.8% | — |