IT
57.977 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.977 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2021-36949 HIGH 7.1 microsoft azure_active_directory_connect Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability 1.4%
CVE-2021-36947 HIGH 8.8 microsoft windows_10 Windows Print Spooler Remote Code Execution Vulnerability 7.5%
CVE-2021-36946 MED 5.4 microsoft dynamics_365_business_central Microsoft Dynamics Business Central Cross-site Scripting Vulnerability 1.0%
CVE-2021-36945 HIGH 7.3 microsoft windows_10_update_assistant Windows 10 Update Assistant Elevation of Privilege Vulnerability 1.9%
CVE-2021-36943 MED 4.0 microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability 0.8%
CVE-2021-36941 HIGH 7.8 microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability 2.2%
CVE-2021-36940 HIGH 7.6 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 4.0%
CVE-2021-36938 MED 5.5 microsoft windows_10 Windows Cryptographic Primitives Library Information Disclosure Vulnerability 0.9%
CVE-2021-36937 HIGH 7.8 microsoft windows_10 Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability 2.3%
CVE-2021-36936 HIGH 8.8 microsoft windows_10 Windows Print Spooler Remote Code Execution Vulnerability 7.4%
CVE-2021-36933 HIGH 7.5 microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability 3.5%
CVE-2021-36932 HIGH 7.5 microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability 3.5%
CVE-2021-36931 MED 4.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.3%
CVE-2021-36930 MED 5.3 microsoft edge Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.1%
CVE-2021-36929 MED 6.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability 3.2%
CVE-2021-36928 MED 6.0 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0.9%
CVE-2021-36927 HIGH 7.8 microsoft windows_7 Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability 0.5%
CVE-2021-36926 HIGH 7.5 microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability 3.5%
CVE-2021-3679 MED 5.5 debian debian_linux A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve 0.7%
CVE-2021-36774 MED 6.5 apache kylin Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server within 1.9%
CVE-2021-36749 MED 6.5 apache druid In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of th 80.9%
CVE-2021-36744 HIGH 7.8 trendmicro maximum_security_2019 Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the system to escalate privileges and create a denial of service. 0.5%
CVE-2021-36739 MED 6.1 apache pluto The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) attacks. 2.3%
CVE-2021-36738 MED 6.1 apache pluto The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the applicant-mvcbean-cdi-jsp-portlet.war artifact 2.3%
CVE-2021-36737 MED 6.1 apache pluto The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the v3-demo-portlet.war artifact 2.3%