58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2021-26433 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 3.5% | — |
| CVE-2021-26432 | CRIT 9.8 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | 11.3% | — |
| CVE-2021-26431 | HIGH 7.8 | microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2021-26430 | MED 6.0 | microsoft azure_sphere Azure Sphere Denial of Service Vulnerability | 0.7% | — |
| CVE-2021-26429 | HIGH 7.7 | microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-26428 | MED 4.4 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-26427 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2021-26426 | HIGH 7.0 | microsoft windows_10 Windows User Account Profile Picture Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-26425 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-26424 | CRIT 9.9 | microsoft windows_10 Windows TCP/IP Remote Code Execution Vulnerability | 61.1% | — |
| CVE-2021-26423 | HIGH 7.5 | microsoft .net .NET Core and Visual Studio Denial of Service Vulnerability | 3.9% | — |
| CVE-2021-26422 | HIGH 7.2 | microsoft lync_server Skype for Business and Lync Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-26421 | MED 6.5 | microsoft lync_server Skype for Business and Lync Spoofing Vulnerability | 1.4% | — |
| CVE-2021-26420 | HIGH 7.1 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 3.0% | — |
| CVE-2021-26419 | HIGH 7.5 | microsoft internet_explorer Scripting Engine Memory Corruption Vulnerability | 22.8% | — |
| CVE-2021-26418 | MED 4.6 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1.2% | — |
| CVE-2021-26417 | MED 5.5 | microsoft windows_10 Windows Overlay Filter Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-26416 | HIGH 7.7 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 3.9% | — |
| CVE-2021-26415 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 3.6% | — |
| CVE-2021-26414 | MED 4.8 | microsoft windows_10 Windows DCOM Server Security Feature Bypass | 49.8% | — |
| CVE-2021-26413 | MED 6.2 | microsoft windows_10 Windows Installer Spoofing Vulnerability | 0.7% | — |
| CVE-2021-26412 | CRIT 9.1 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 33.8% | — |
| CVE-2021-26334 | CRIT 9.9 | amd amd_uprof The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user. | 1.2% | — |
| CVE-2021-26296 | HIGH 7.5 | apache myfaces In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possi | 2.9% | — |
| CVE-2021-26295 | CRIT 9.8 | apache ofbiz Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz. | 97.8% | — |