IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2021-41344 HIGH 8.1 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 6.5% —
CVE-2021-41343 MED 5.5 microsoft windows_10 Windows Fast FAT File System Driver Information Disclosure Vulnerability 0.7% —
CVE-2021-41342 MED 6.8 microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability 1.6% —
CVE-2021-41340 HIGH 7.8 microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability 2.0% —
CVE-2021-41339 MED 4.7 microsoft windows_10 Microsoft DWM Core Library Elevation of Privilege Vulnerability 0.5% —
CVE-2021-41338 MED 5.5 microsoft windows_10 Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability 3.3% —
CVE-2021-41337 MED 4.9 microsoft windows_server_2016 Active Directory Security Feature Bypass Vulnerability 1.6% —
CVE-2021-41336 MED 5.5 microsoft windows_11 Windows Kernel Information Disclosure Vulnerability 0.7% —
CVE-2021-41335 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.4% —
CVE-2021-41334 HIGH 7.0 microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability 0.4% —
CVE-2021-41333 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 1.1% —
CVE-2021-41332 MED 6.5 microsoft windows_10 Windows Print Spooler Information Disclosure Vulnerability 2.7% —
CVE-2021-41331 HIGH 7.8 microsoft windows_10 Windows Media Audio Decoder Remote Code Execution Vulnerability 2.0% —
CVE-2021-41330 HIGH 7.8 microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 2.0% —
CVE-2021-41303 CRIT 9.8 apache shiro Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0. 76.7% —
CVE-2021-41079 HIGH 7.5 apache tomcat Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loo 7.2% —
CVE-2021-41073 HIGH 7.8 debian debian_linux loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation. 1.8% —
CVE-2021-41057 HIGH 7.1 siemens pss_cape In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions. 0.3% —
CVE-2021-4104 HIGH 7.5 apache log4j JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to per 81.1% —
CVE-2021-41032 MED 6.3 fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDOMs us 0.6% —
CVE-2021-41031 HIGH 7.8 fortinet forticlient A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior and 6.2.9 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for FortiESN 0.5% —
CVE-2021-41030 MED 5.4 fortinet forticlient_enterprise_management_server An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unauthenticated attacker to impersonate an existing user by intercepting and re-using valid SAML authentication mess 1.0% —
CVE-2021-41029 MED 6.4 fortinet fortiwlm A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to store malicious javascript code in the device and trigger it via crafted HTTP requests 0.5% —
CVE-2021-41028 HIGH 8.2 fortinet forticlient A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 an 0.2% —
CVE-2021-41027 HIGH 7.3 fortinet fortiweb A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute unauthorized code or commands via crafted certificates loaded into the device. 0.2% —