58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2021-3864 | HIGH 7.0 | debian debian_linux A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then ha | 0.8% | — |
| CVE-2021-38639 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2021-38638 | HIGH 7.8 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38637 | MED 5.5 | microsoft windows_10 Windows Storage Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-38636 | MED 5.5 | microsoft windows_10 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-38635 | MED 5.5 | microsoft windows_10 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-38634 | HIGH 7.1 | microsoft windows_10 Microsoft Windows Update Client Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-38633 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-38632 | MED 5.7 | microsoft windows_10 Windows BitLocker Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2021-38631 | MED 4.4 | microsoft windows_10 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | 1.9% | — |
| CVE-2021-38630 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38629 | MED 6.5 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability | 2.7% | — |
| CVE-2021-38628 | HIGH 7.8 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38626 | HIGH 7.8 | microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38625 | HIGH 7.8 | microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38624 | MED 6.5 | microsoft windows_10 Windows Key Storage Provider Security Feature Bypass Vulnerability | 1.5% | — |
| CVE-2021-38571 | HIGH 7.8 | foxitsoftware foxit_reader An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502. | 0.5% | — |
| CVE-2021-38555 | CRIT 9.1 | apache any23 An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to int | 2.8% | — |
| CVE-2021-38542 | MED 5.9 | apache james Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information. | 2.3% | — |
| CVE-2021-38540 | CRIT 9.8 | apache airflow The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclos | 80.9% | — |
| CVE-2021-38505 | MED 6.5 | mozilla firefox Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data fro | 1.1% | — |
| CVE-2021-38492 | MED 6.5 | mozilla firefox When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating sys | 1.2% | — |
| CVE-2021-3848 | MED 5.5 | trendmicro apex_one An arbitrary file creation by privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1, and Worry-Free Business Security Services could allow a local attacker to create an arbitrary file with high | 0.2% | — |
| CVE-2021-3847 | HIGH 7.8 | fedoraproject fedora An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate thei | 0.5% | — |
| CVE-2021-38300 | HIGH 7.8 | debian debian_linux arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel context. This occurs because conditional branches can exceed th | 0.6% | — |