IT
58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.414 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2021-27050 HIGH 7.8 microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability 2.5% —
CVE-2021-27049 HIGH 7.8 microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability 2.5% —
CVE-2021-27048 HIGH 7.8 microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability 2.5% —
CVE-2021-27047 HIGH 7.8 microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability 2.7% —
CVE-2021-26987 CRIT 9.8 netapp element_plug-in_for_vcenter_server Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCe 2.4% —
CVE-2021-26934 HIGH 7.8 fedoraproject fedora An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration, but this wasn't stated accordingly in its support status en 0.3% —
CVE-2021-26932 MED 5.5 debian debian_linux An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in batch hypercalls, where a number of operations are done in a single hypercall, the success or failure of each one is reported to the backen 0.3% —
CVE-2021-26931 MED 5.5 debian debian_linux An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at least under the influence of guests (suc 0.6% —
CVE-2021-26930 HIGH 7.8 debian debian_linux An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service requests to the PV backend, the driver maps grant references provided by the frontend. In this process, errors may be encountered. In one case, an error encountered ea 0.3% —
CVE-2021-26920 MED 6.5 apache druid In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of th 9.5% —
CVE-2021-26919 HIGH 8.8 apache druid Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissions to set up lookups or submit ingestion tasks. The MySQL JDBC driver supports certain properties, which, if le 22.8% —
CVE-2021-26902 HIGH 7.8 microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability 5.5% —
CVE-2021-26901 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.8% —
CVE-2021-26900 HIGH 7.8 microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability 2.4% —
CVE-2021-26899 HIGH 7.8 microsoft windows_10 Windows UPnP Device Host Elevation of Privilege Vulnerability 1.0% —
CVE-2021-26898 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.9% —
CVE-2021-26897 CRIT 9.8 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 11.6% —
CVE-2021-26896 HIGH 7.5 microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability 7.4% —
CVE-2021-26895 CRIT 9.8 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 7.3% —
CVE-2021-26894 CRIT 9.8 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 7.3% —
CVE-2021-26893 CRIT 9.8 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 7.0% —
CVE-2021-26892 MED 6.2 microsoft windows_10 Windows Extensible Firmware Interface Security Feature Bypass Vulnerability 1.2% —
CVE-2021-26891 HIGH 7.8 microsoft windows_10 Windows Container Execution Agent Elevation of Privilege Vulnerability 0.9% —
CVE-2021-26890 HIGH 7.8 microsoft windows_10 Application Virtualization Remote Code Execution Vulnerability 0.8% —
CVE-2021-26889 HIGH 7.8 microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability 1.1% —