IT
58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.414 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2021-26617 HIGH 8.1 firstmall firstmall This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows remote attackers to execute malicious code in Firstmall via navercheckout_add function. 1.3% —
CVE-2021-26615 HIGH 7.8 bandisoft ark_library ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW function because of an integer overflow. 0.7% —
CVE-2021-26613 HIGH 8.1 tobesoft nexacro improper input validation vulnerability in nexacro permits copying file to the startup folder using rename method. 0.8% —
CVE-2021-26612 HIGH 8.1 tobesoft nexacro An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code. 1.2% —
CVE-2021-26610 HIGH 7.2 nhn-commerce godomall5 The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code. 0.5% —
CVE-2021-26608 HIGH 8.8 handysoft hshell An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash. 0.6% —
CVE-2021-26607 HIGH 8.1 tobesoft nexacro An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems. 1.9% —
CVE-2021-26606 CRIT 9.8 dreamsecurity magicline4nx.exe A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certificate. An attacker could exploit this vulnerability by sending a crafted HTTP re 2.4% —
CVE-2021-26605 HIGH 7.5 unidocs ezpdfreader An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication. 1.0% —
CVE-2021-26603 HIGH 8.6 bandisoft ark_library A heap overflow issue was found in ARK library of bandisoft Co., Ltd when the Ark_DigPathA function parsed a file path. This vulnerability is due to missing support for string length check. 0.7% —
CVE-2021-26582 MED 6.1 hp icewall_sso_dgfw A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS). 0.7% —
CVE-2021-26559 MED 6.5 apache airflow Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg` 2.8% —
CVE-2021-26558 HIGH 7.5 apache shardingsphere-ui Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache ShardingSphere-UI versi 2.5% —
CVE-2021-26544 MED 5.4 apache livy Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. This issue is fixed in L 2.8% —
CVE-2021-26472 CRIT 10.0 vembu bdr_suite In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using this command argument an unauthenticated attacker can execute arbitrary OS commands with SYSTEM privileges. 2.5% —
CVE-2021-26461 CRIT 9.8 apache nuttx Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code in 5.0% —
CVE-2021-26444 LOW 3.3 microsoft azure_real_time_operating_system Azure RTOS Information Disclosure Vulnerability 1.6% —
CVE-2021-26443 CRIT 9.0 microsoft windows_10 Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability 1.7% —
CVE-2021-26442 HIGH 7.0 microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability 0.8% —
CVE-2021-26441 HIGH 7.8 microsoft windows_10 Storage Spaces Controller Elevation of Privilege Vulnerability 0.9% —
CVE-2021-26439 MED 4.6 microsoft edge Microsoft Edge for Android Information Disclosure Vulnerability 2.9% —
CVE-2021-26437 MED 5.5 microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability 2.3% —
CVE-2021-26436 MED 6.1 microsoft edge Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 2.7% —
CVE-2021-26435 HIGH 8.1 microsoft windows_10 Windows Scripting Engine Memory Corruption Vulnerability 5.3% —
CVE-2021-26434 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability 0.9% —