58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2021-26617 | HIGH 8.1 | firstmall firstmall This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows remote attackers to execute malicious code in Firstmall via navercheckout_add function. | 1.3% | — |
| CVE-2021-26615 | HIGH 7.8 | bandisoft ark_library ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW function because of an integer overflow. | 0.7% | — |
| CVE-2021-26613 | HIGH 8.1 | tobesoft nexacro improper input validation vulnerability in nexacro permits copying file to the startup folder using rename method. | 0.8% | — |
| CVE-2021-26612 | HIGH 8.1 | tobesoft nexacro An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code. | 1.2% | — |
| CVE-2021-26610 | HIGH 7.2 | nhn-commerce godomall5 The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code. | 0.5% | — |
| CVE-2021-26608 | HIGH 8.8 | handysoft hshell An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash. | 0.6% | — |
| CVE-2021-26607 | HIGH 8.1 | tobesoft nexacro An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems. | 1.9% | — |
| CVE-2021-26606 | CRIT 9.8 | dreamsecurity magicline4nx.exe A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certificate. An attacker could exploit this vulnerability by sending a crafted HTTP re | 2.4% | — |
| CVE-2021-26605 | HIGH 7.5 | unidocs ezpdfreader An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication. | 1.0% | — |
| CVE-2021-26603 | HIGH 8.6 | bandisoft ark_library A heap overflow issue was found in ARK library of bandisoft Co., Ltd when the Ark_DigPathA function parsed a file path. This vulnerability is due to missing support for string length check. | 0.7% | — |
| CVE-2021-26582 | MED 6.1 | hp icewall_sso_dgfw A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS). | 0.7% | — |
| CVE-2021-26559 | MED 6.5 | apache airflow Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg` | 2.8% | — |
| CVE-2021-26558 | HIGH 7.5 | apache shardingsphere-ui Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache ShardingSphere-UI versi | 2.5% | — |
| CVE-2021-26544 | MED 5.4 | apache livy Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. This issue is fixed in L | 2.8% | — |
| CVE-2021-26472 | CRIT 10.0 | vembu bdr_suite In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using this command argument an unauthenticated attacker can execute arbitrary OS commands with SYSTEM privileges. | 2.5% | — |
| CVE-2021-26461 | CRIT 9.8 | apache nuttx Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code in | 5.0% | — |
| CVE-2021-26444 | LOW 3.3 | microsoft azure_real_time_operating_system Azure RTOS Information Disclosure Vulnerability | 1.6% | — |
| CVE-2021-26443 | CRIT 9.0 | microsoft windows_10 Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2021-26442 | HIGH 7.0 | microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-26441 | HIGH 7.8 | microsoft windows_10 Storage Spaces Controller Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-26439 | MED 4.6 | microsoft edge Microsoft Edge for Android Information Disclosure Vulnerability | 2.9% | — |
| CVE-2021-26437 | MED 5.5 | microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability | 2.3% | — |
| CVE-2021-26436 | MED 6.1 | microsoft edge Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2021-26435 | HIGH 8.1 | microsoft windows_10 Windows Scripting Engine Memory Corruption Vulnerability | 5.3% | — |
| CVE-2021-26434 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability | 0.9% | — |