58.061 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.061 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2021-30621 | MED 6.5 | fedoraproject fedora Chromium: CVE-2021-30621 UI Spoofing in Autofill | 3.5% | — |
| CVE-2021-30620 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink | 4.1% | — |
| CVE-2021-3062 | HIGH 8.1 | paloaltonetworks pan-os An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS. Exploitation of this | 0.7% | — |
| CVE-2021-30619 | MED 6.5 | fedoraproject fedora Chromium: CVE-2021-30619 UI Spoofing in Autofill | 3.5% | — |
| CVE-2021-30618 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30618 Inappropriate implementation in DevTools | 4.1% | — |
| CVE-2021-30617 | MED 6.5 | fedoraproject fedora Chromium: CVE-2021-30617 Policy bypass in Blink | 3.7% | — |
| CVE-2021-30616 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30616 Use after free in Media | 4.1% | — |
| CVE-2021-30615 | MED 6.5 | fedoraproject fedora Chromium: CVE-2021-30615 Cross-origin data leak in Navigation | 5.6% | — |
| CVE-2021-30614 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip | 4.5% | — |
| CVE-2021-30613 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30613 Use after free in Base internals | 4.1% | — |
| CVE-2021-30612 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30612 Use after free in WebRTC | 2.8% | — |
| CVE-2021-30611 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30611 Use after free in WebRTC | 2.8% | — |
| CVE-2021-30610 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30610 Use after free in Extensions API | 4.1% | — |
| CVE-2021-3061 | MED 6.4 | paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions e | 0.9% | — |
| CVE-2021-30609 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30609 Use after free in Sign-In | 4.2% | — |
| CVE-2021-30608 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30608 Use after free in Web Share | 4.1% | — |
| CVE-2021-30607 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30607 Use after free in Permissions | 4.1% | — |
| CVE-2021-30606 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30606 Use after free in Blink | 4.1% | — |
| CVE-2021-30605 | HIGH 7.8 | google chrome_os_readiness_tool Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls. | 0.1% | — |
| CVE-2021-3060 | HIGH 8.1 | paloaltonetworks pan-os An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root use | 33.9% | — |
| CVE-2021-3059 | HIGH 8.1 | paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerability enables a man-in-the-middle attacker to execute arbitrary OS commands to escalate privileges. This issue impa | 1.5% | — |
| CVE-2021-3058 | HIGH 8.8 | paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 vers | 1.6% | — |
| CVE-2021-3057 | HIGH 8.1 | paloaltonetworks globalprotect A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This issue impacts: GlobalProtec | 1.4% | — |
| CVE-2021-30565 | HIGH 8.8 | fedoraproject fedora Out of bounds write in Tab Groups in Google Chrome on Linux and ChromeOS prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page. | 1.9% | — |
| CVE-2021-3056 | HIGH 8.8 | paloaltonetworks pan-os A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than P | 1.5% | — |