58.352 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.352 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2021-30613 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30613 Use after free in Base internals | 4.1% | — |
| CVE-2021-30612 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30612 Use after free in WebRTC | 2.8% | — |
| CVE-2021-30611 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30611 Use after free in WebRTC | 2.8% | — |
| CVE-2021-30610 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30610 Use after free in Extensions API | 4.1% | — |
| CVE-2021-3061 | MED 6.4 | paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions e | 0.9% | — |
| CVE-2021-30609 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30609 Use after free in Sign-In | 4.1% | — |
| CVE-2021-30608 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30608 Use after free in Web Share | 4.1% | — |
| CVE-2021-30607 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30607 Use after free in Permissions | 4.1% | — |
| CVE-2021-30606 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30606 Use after free in Blink | 4.1% | — |
| CVE-2021-30605 | HIGH 7.8 | google chrome_os_readiness_tool Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls. | 0.1% | — |
| CVE-2021-3060 | HIGH 8.1 | paloaltonetworks pan-os An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root use | 33.9% | — |
| CVE-2021-3059 | HIGH 8.1 | paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerability enables a man-in-the-middle attacker to execute arbitrary OS commands to escalate privileges. This issue impa | 1.5% | — |
| CVE-2021-3058 | HIGH 8.8 | paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 vers | 1.6% | — |
| CVE-2021-3057 | HIGH 8.1 | paloaltonetworks globalprotect A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This issue impacts: GlobalProtec | 1.4% | — |
| CVE-2021-30565 | HIGH 8.8 | fedoraproject fedora Out of bounds write in Tab Groups in Google Chrome on Linux and ChromeOS prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page. | 1.9% | — |
| CVE-2021-3056 | HIGH 8.8 | paloaltonetworks pan-os A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than P | 1.5% | — |
| CVE-2021-3055 | MED 6.5 | paloaltonetworks pan-os An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the fi | 1.1% | — |
| CVE-2021-3054 | HIGH 7.2 | paloaltonetworks pan-os A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges. This issue impacts | 0.9% | — |
| CVE-2021-3053 | HIGH 7.5 | paloaltonetworks pan-os An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to crash. Re | 1.0% | — |
| CVE-2021-3052 | HIGH 8.0 | paloaltonetworks pan-os A reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface enables an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performs arbitrar | 0.6% | — |
| CVE-2021-3051 | HIGH 8.1 | paloaltonetworks cortex_xsoar An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform u | 0.6% | — |
| CVE-2021-3050 | HIGH 8.8 | paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 9.0 version 9.0.10 through PAN-OS 9.0.14; PAN-OS 9.1 | 1.8% | — |
| CVE-2021-30490 | HIGH 7.8 | power-software-download viewpower upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticated User to modify files, allowing for privilege escalation. | 0.3% | — |
| CVE-2021-3049 | LOW 2.6 | paloaltonetworks cortex_xsoar An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part | 0.5% | — |
| CVE-2021-30480 | HIGH 8.5 | zoom chat Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: | 5.8% | — |