IT
57.977 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.977 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2021-38636 MED 5.5 microsoft windows_10 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability 0.9%
CVE-2021-38635 MED 5.5 microsoft windows_10 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability 0.9%
CVE-2021-38634 HIGH 7.1 microsoft windows_10 Microsoft Windows Update Client Elevation of Privilege Vulnerability 0.9%
CVE-2021-38633 HIGH 7.8 microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability 1.0%
CVE-2021-38632 MED 5.7 microsoft windows_10 Windows BitLocker Security Feature Bypass Vulnerability 0.8%
CVE-2021-38631 MED 4.4 microsoft windows_10 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability 1.9%
CVE-2021-38630 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.5%
CVE-2021-38629 MED 6.5 microsoft windows_10 Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability 2.7%
CVE-2021-38628 HIGH 7.8 microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 0.5%
CVE-2021-38626 HIGH 7.8 microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2021-38625 HIGH 7.8 microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2021-38624 MED 6.5 microsoft windows_10 Windows Key Storage Provider Security Feature Bypass Vulnerability 1.5%
CVE-2021-38571 HIGH 7.8 foxitsoftware foxit_reader An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502. 0.5%
CVE-2021-38555 CRIT 9.1 apache any23 An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to int 2.8%
CVE-2021-38542 MED 5.9 apache james Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information. 2.3%
CVE-2021-38540 CRIT 9.8 apache airflow The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclos 80.9%
CVE-2021-38505 MED 6.5 mozilla firefox Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data fro 1.1%
CVE-2021-38492 MED 6.5 mozilla firefox When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating sys 1.2%
CVE-2021-3848 MED 5.5 trendmicro apex_one An arbitrary file creation by privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1, and Worry-Free Business Security Services could allow a local attacker to create an arbitrary file with high 0.2%
CVE-2021-3847 HIGH 7.8 fedoraproject fedora An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate thei 0.5%
CVE-2021-38300 HIGH 7.8 debian debian_linux arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel context. This occurs because conditional branches can exceed th 0.6%
CVE-2021-38296 HIGH 7.5 apache spark Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an i 1.8%
CVE-2021-38295 HIGH 7.3 apache couchdb In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code em 2.5%
CVE-2021-38294 CRIT 9.8 apache storm A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentic 84.5%
CVE-2021-38209 LOW 3.3 linux linux_kernel net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net namespace because these changes are leaked into all other net namespaces. This is related to the NF_SYSCTL_CT_MAX, NF_SYSCTL_CT_EXPECT_MAX, and N 0.3%