58.415 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.415 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2021-26093 | HIGH 7.3 | fortinet fortiwlc An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash the access point being managed by the controller by executing a crafted CLI command. | 0.2% | — |
| CVE-2021-26092 | MED 4.7 | fortinet fortios Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.12, 6.2.0 through 6.2.7, 6.4.0 through 6.4.4; and FortiProxy 1.2.0 through 1.2.9, 2.0.0 through 2.0.1 may allow | 1.1% | — |
| CVE-2021-26091 | HIGH 7.5 | fortinet fortimail A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to infer parts of users | 0.3% | — |
| CVE-2021-26090 | MED 5.3 | fortinet fortimail A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 may allow an unauthenticated remote attacker to exhaust available memory via specifically crafted login requests. | 1.3% | — |
| CVE-2021-26089 | MED 6.7 | fortinet forticlient An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitrary privileged shell commands during installation phase. | 0.4% | — |
| CVE-2021-26088 | HIGH 7.1 | fortinet fortinet_single_sign-on An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets. | 1.0% | — |
| CVE-2021-26087 | MED 4.3 | fortinet fortiwlc An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface may allow both authenticated remote attackers and non-authenticated attackers in the same ne | 0.3% | — |
| CVE-2021-25958 | MED 6.5 | apache ofbiz In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he | 2.6% | — |
| CVE-2021-25736 | MED 5.8 | kubernetes kubernetes Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not set the “status.loadBalancer.ingress[].ip” field. Clusters w | 0.9% | — |
| CVE-2021-25646 | HIGH 8.8 | apache druid Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possibl | 99.0% | — |
| CVE-2021-25642 | HIGH 8.8 | apache hadoop ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users shou | 2.2% | — |
| CVE-2021-25641 | CRIT 9.8 | apache dubbo Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before 2.7.8 or 2.6.9, an attacker can choose which serialization id the Provider will use by tampering with the byte | 21.2% | — |
| CVE-2021-25640 | MED 6.1 | apache dubbo In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability. | 2.1% | — |
| CVE-2021-25329 | HIGH 7.0 | apache tomcat The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE | 9.5% | — |
| CVE-2021-25265 | HIGH 8.8 | sophos connect A malicious website could execute code remotely in Sophos Connect Client before version 2.1. | 1.8% | — |
| CVE-2021-25261 | HIGH 7.8 | yandex yandex_browser Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process | 0.5% | — |
| CVE-2021-25252 | MED 5.5 | trendmicro apex_central Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file. | 0.6% | — |
| CVE-2021-25251 | HIGH 7.2 | trendmicro antivirus\+_security_2020 The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to disable the program's password protection and disable protection. An attacker must already have administrator | 2.6% | — |
| CVE-2021-25249 | HIGH 7.8 | trendmicro apex_one An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. P | 0.4% | — |
| CVE-2021-25248 | MED 5.5 | trendmicro apex_one An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Ple | 0.9% | — |
| CVE-2021-25247 | HIGH 7.8 | trendmicro housecall_for_home_networks A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker to use a malicious DLL to escalate privileges and perform arbitrary code execution. An attacker must already have user privileges on the ma | 0.7% | — |
| CVE-2021-25243 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain patch level information. | 2.2% | — |
| CVE-2021-25242 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain version and build information. | 2.2% | — |
| CVE-2021-25241 | MED 5.3 | trendmicro apex_one A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a sweep. | 1.9% | — |
| CVE-2021-25240 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain x64 agent hofitx information. | 2.1% | — |