58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2021-40701 | HIGH 7.8 | adobe premiere_elements Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious m4a file, potentially resulting in arbitrary code execution in the context of the current user. User interaction | 1.7% | — |
| CVE-2021-40700 | HIGH 7.8 | adobe premiere_elements Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interactio | 1.7% | — |
| CVE-2021-40690 | HIGH 7.5 | apache cxf All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse | 7.4% | — |
| CVE-2021-40683 | HIGH 7.8 | akamai enterprise_application_access In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution. | 0.4% | — |
| CVE-2021-40525 | CRIT 9.1 | apache james Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. D | 3.7% | — |
| CVE-2021-40490 | HIGH 7.0 | debian debian_linux A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13. | 0.3% | — |
| CVE-2021-40489 | HIGH 7.8 | microsoft windows_10 Storage Spaces Controller Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-40488 | HIGH 7.8 | microsoft windows_10 Storage Spaces Controller Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-40487 | HIGH 8.1 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 48.2% | — |
| CVE-2021-40486 | HIGH 7.8 | microsoft office Microsoft Word Remote Code Execution Vulnerability | 6.0% | — |
| CVE-2021-40485 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-40484 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.4% | — |
| CVE-2021-40483 | HIGH 7.6 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 1.4% | — |
| CVE-2021-40482 | MED 5.3 | microsoft sharepoint_server Microsoft SharePoint Server Information Disclosure Vulnerability | 2.3% | — |
| CVE-2021-40481 | HIGH 7.1 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 5.9% | — |
| CVE-2021-40480 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 5.7% | — |
| CVE-2021-40479 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-40478 | HIGH 7.8 | microsoft windows_10 Storage Spaces Controller Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-40477 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-40476 | HIGH 7.5 | microsoft windows_10 Windows AppContainer Elevation Of Privilege Vulnerability | 2.4% | — |
| CVE-2021-40475 | MED 5.5 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-40474 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-40473 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-40472 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-40471 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |