58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2021-37150 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. | 2.1% | — |
| CVE-2021-3715 | HIGH 7.8 | linux linux_kernel A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escal | 0.4% | — |
| CVE-2021-37149 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. | 2.6% | — |
| CVE-2021-37148 | HIGH 7.5 | apache traffic_server Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1. | 2.6% | — |
| CVE-2021-37147 | HIGH 7.5 | apache traffic_server Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. | 2.5% | — |
| CVE-2021-3714 | MED 5.9 | linux linux_kernel A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the | 1.5% | — |
| CVE-2021-36975 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2021-36974 | HIGH 7.8 | microsoft windows_10 Windows SMB Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36973 | HIGH 7.8 | microsoft windows_10 Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36972 | MED 5.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-36970 | HIGH 8.8 | microsoft windows_10 Windows Print Spooler Spoofing Vulnerability | 3.1% | — |
| CVE-2021-36969 | MED 5.5 | microsoft windows_10 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-36968 | HIGH 7.8 | microsoft windows_7 Windows DNS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36967 | HIGH 8.0 | microsoft windows_10 Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-36966 | HIGH 7.8 | microsoft windows_10 Windows Subsystem for Linux Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36965 | HIGH 8.8 | microsoft windows_10 Windows WLAN AutoConfig Service Remote Code Execution Vulnerability | 4.6% | — |
| CVE-2021-36964 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36963 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-36962 | MED 5.5 | microsoft windows_10 Windows Installer Information Disclosure Vulnerability | 1.3% | — |
| CVE-2021-36961 | MED 5.5 | microsoft windows_10 Windows Installer Denial of Service Vulnerability | 1.1% | — |
| CVE-2021-36960 | HIGH 7.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 3.3% | — |
| CVE-2021-36959 | MED 5.5 | microsoft windows_10 Windows Authenticode Spoofing Vulnerability | 1.3% | — |
| CVE-2021-36958 | HIGH 7.8 | microsoft windows A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the | 30.6% | — |
| CVE-2021-36957 | HIGH 7.8 | microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36956 | MED 4.4 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0.9% | — |