58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2021-28329 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28328 | MED 6.5 | microsoft windows_10 Windows DNS Information Disclosure Vulnerability | 2.5% | — |
| CVE-2021-28327 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-28326 | MED 5.5 | microsoft windows_10 Windows AppX Deployment Server Denial of Service Vulnerability | 1.0% | — |
| CVE-2021-28325 | MED 6.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 62.1% | — |
| CVE-2021-28324 | HIGH 7.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 6.2% | — |
| CVE-2021-28323 | MED 6.5 | microsoft windows_10 Windows DNS Information Disclosure Vulnerability | 4.3% | — |
| CVE-2021-28322 | HIGH 7.8 | microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-28321 | HIGH 7.8 | microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2021-28320 | HIGH 7.8 | microsoft windows_10 Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-28319 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability | 9.4% | — |
| CVE-2021-28318 | MED 5.5 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28317 | MED 5.5 | microsoft windows_10 Microsoft Windows Codecs Library Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28316 | MED 4.2 | microsoft windows_10 Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2021-28315 | HIGH 7.8 | microsoft windows_10 Windows Media Video Decoder Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2021-28314 | HIGH 7.8 | microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-28313 | HIGH 7.8 | microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-28312 | LOW 3.3 | microsoft windows_10 Windows NTFS Denial of Service Vulnerability | 6.6% | — |
| CVE-2021-28311 | MED 6.5 | microsoft windows_10 Windows Application Compatibility Cache Denial of Service Vulnerability | 2.5% | — |
| CVE-2021-28309 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28163 | LOW 2.7 | apache ignite In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and | 4.2% | — |
| CVE-2021-28131 | HIGH 7.5 | apache impala Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with access to the logs can use another authenticated user's sessions with specially | 3.3% | — |
| CVE-2021-28130 | HIGH 7.8 | drweb security_space Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload within a legitimate binary (e.g., frwl_svc.exe) bypasses firewall filters. | 0.4% | — |
| CVE-2021-28129 | HIGH 7.8 | apache openoffice While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by t | 0.5% | — |
| CVE-2021-28125 | MED 6.1 | apache superset Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard | 64.0% | — |