58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2021-28317 | MED 5.5 | microsoft windows_10 Microsoft Windows Codecs Library Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28316 | MED 4.2 | microsoft windows_10 Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2021-28315 | HIGH 7.8 | microsoft windows_10 Windows Media Video Decoder Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2021-28314 | HIGH 7.8 | microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-28313 | HIGH 7.8 | microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-28312 | LOW 3.3 | microsoft windows_10 Windows NTFS Denial of Service Vulnerability | 6.6% | — |
| CVE-2021-28311 | MED 6.5 | microsoft windows_10 Windows Application Compatibility Cache Denial of Service Vulnerability | 2.5% | — |
| CVE-2021-28309 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28163 | LOW 2.7 | apache ignite In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and | 4.2% | — |
| CVE-2021-28131 | HIGH 7.5 | apache impala Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with access to the logs can use another authenticated user's sessions with specially | 3.3% | — |
| CVE-2021-28130 | HIGH 7.8 | drweb security_space Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload within a legitimate binary (e.g., frwl_svc.exe) bypasses firewall filters. | 0.4% | — |
| CVE-2021-28129 | HIGH 7.8 | apache openoffice While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by t | 0.5% | — |
| CVE-2021-28125 | MED 6.1 | apache superset Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard | 64.0% | — |
| CVE-2021-28039 | MED 6.5 | linux linux_kernel An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical | 0.4% | — |
| CVE-2021-28038 | MED 6.5 | debian debian_linux An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host | 0.7% | — |
| CVE-2021-27907 | MED 5.4 | apache superset Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user could inject javascript code executing unwanted action in the c | 86.4% | — |
| CVE-2021-27906 | MED 5.5 | apache pdfbox A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. | 3.3% | — |
| CVE-2021-27905 | CRIT 9.8 | apache solr The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the loca | 93.1% | — |
| CVE-2021-27893 | HIGH 7.0 | ssh tectia_client SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. ConnectSecure on Windows is affected. | 0.4% | — |
| CVE-2021-27892 | HIGH 7.8 | ssh tectia_client SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation. ConnectSecure on Windows is affected. | 0.3% | — |
| CVE-2021-27891 | HIGH 8.8 | ssh tectia_client SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected. | 1.0% | — |
| CVE-2021-27853 | MED 4.7 | cisco catalyst_6503-e_firmware Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers. | 0.8% | — |
| CVE-2021-27850 | CRIT 9.8 | apache tapestry A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The vulnerability I have found is a bypass of the fix for CVE-2019-0195. Recap: Before | 93.5% | — |
| CVE-2021-27807 | MED 5.5 | apache pdfbox A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. | 3.0% | — |
| CVE-2021-27738 | HIGH 7.5 | apache kylin All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any security checks, which allowed an unauthenticated user to issue arbitrary requests, such as assigning/unassigning | 2.6% | — |