57.977 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.977 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2021-36949 | HIGH 7.1 | microsoft azure_active_directory_connect Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability | 1.4% | — |
| CVE-2021-36947 | HIGH 8.8 | microsoft windows_10 Windows Print Spooler Remote Code Execution Vulnerability | 7.5% | — |
| CVE-2021-36946 | MED 5.4 | microsoft dynamics_365_business_central Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | 1.0% | — |
| CVE-2021-36945 | HIGH 7.3 | microsoft windows_10_update_assistant Windows 10 Update Assistant Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2021-36943 | MED 4.0 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-36941 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-36940 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 4.0% | — |
| CVE-2021-36938 | MED 5.5 | microsoft windows_10 Windows Cryptographic Primitives Library Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-36937 | HIGH 7.8 | microsoft windows_10 Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-36936 | HIGH 8.8 | microsoft windows_10 Windows Print Spooler Remote Code Execution Vulnerability | 7.4% | — |
| CVE-2021-36933 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 3.5% | — |
| CVE-2021-36932 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 3.5% | — |
| CVE-2021-36931 | MED 4.4 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2021-36930 | MED 5.3 | microsoft edge Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-36929 | MED 6.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 3.2% | — |
| CVE-2021-36928 | MED 6.0 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-36927 | HIGH 7.8 | microsoft windows_7 Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36926 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 3.5% | — |
| CVE-2021-3679 | MED 5.5 | debian debian_linux A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve | 0.7% | — |
| CVE-2021-36774 | MED 6.5 | apache kylin Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server within | 1.9% | — |
| CVE-2021-36749 | MED 6.5 | apache druid In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of th | 80.9% | — |
| CVE-2021-36744 | HIGH 7.8 | trendmicro maximum_security_2019 Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the system to escalate privileges and create a denial of service. | 0.5% | — |
| CVE-2021-36739 | MED 6.1 | apache pluto The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) attacks. | 2.3% | — |
| CVE-2021-36738 | MED 6.1 | apache pluto The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the applicant-mvcbean-cdi-jsp-portlet.war artifact | 2.3% | — |
| CVE-2021-36737 | MED 6.1 | apache pluto The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the v3-demo-portlet.war artifact | 2.3% | — |