58.061 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.061 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2021-31179 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 13.5% | — |
| CVE-2021-31178 | MED 5.5 | microsoft 365_apps Microsoft Office Information Disclosure Vulnerability | 16.0% | — |
| CVE-2021-31177 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2021-31176 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 3.0% | — |
| CVE-2021-31175 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2021-31174 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 2.9% | — |
| CVE-2021-31173 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Server Information Disclosure Vulnerability | 2.1% | — |
| CVE-2021-31172 | HIGH 7.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1.8% | — |
| CVE-2021-31171 | MED 4.1 | microsoft sharepoint_foundation Microsoft SharePoint Information Disclosure Vulnerability | 0.6% | — |
| CVE-2021-31170 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-31169 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-31168 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-31167 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-31165 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-31164 | HIGH 7.5 | apache unomi Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements. | 2.3% | — |
| CVE-2021-3115 | HIGH 7.5 | fedoraproject fedora Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download). | 6.5% | — |
| CVE-2021-30641 | MED 5.3 | apache http_server Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF' | 52.6% | — |
| CVE-2021-30640 | MED 6.5 | apache tomcat A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to | 9.9% | — |
| CVE-2021-3064 | CRIT 9.8 | paloaltonetworks pan-os A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges. The attac | 20.1% | — |
| CVE-2021-30639 | HIGH 7.5 | apache tomcat A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was not reset be | 6.9% | — |
| CVE-2021-30638 | HIGH 7.5 | apache tapestry Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-13953. This issue affects Apache Tapestr | 6.6% | — |
| CVE-2021-3063 | HIGH 7.5 | paloaltonetworks pan-os An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to send specifically crafted traffic to a GlobalProtect interface that | 0.9% | — |
| CVE-2021-30624 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30624 Use after free in Autofill | 4.1% | — |
| CVE-2021-30623 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30623 Use after free in Bookmarks | 4.0% | — |
| CVE-2021-30622 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30622 Use after free in WebApp Installs | 4.1% | — |