58.415 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.415 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2021-25239 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about x86 agent hotfixes. | 2.1% | — |
| CVE-2021-25238 | MED 5.3 | trendmicro officescan An improper access control information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about an agent's managing port. | 2.1% | — |
| CVE-2021-25237 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem) could allow an unauthenticated user to obtain information about the managing port used by agents. | 1.6% | — |
| CVE-2021-25236 | MED 5.3 | trendmicro officescan A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a specific sweep. | 1.9% | — |
| CVE-2021-25235 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about a content inspection configuration file. | 2.1% | — |
| CVE-2021-25234 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific notification configuration file. | 2.1% | — |
| CVE-2021-25233 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific configuration download file. | 2.1% | — |
| CVE-2021-25232 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the SQL database. | 2.0% | — |
| CVE-2021-25231 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific hotfix history file. | 2.2% | — |
| CVE-2021-25230 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the contents of a scan connection exception file. | 2.1% | — |
| CVE-2021-25220 | MED 6.8 | fedoraproject fedora BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to | 3.4% | — |
| CVE-2021-25195 | HIGH 7.8 | microsoft windows_10 Windows PKU2U Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-25122 | HIGH 7.5 | apache tomcat When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could | 18.1% | — |
| CVE-2021-24122 | MED 5.9 | apache tomcat When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root c | 22.9% | — |
| CVE-2021-24117 | MED 4.9 | apache teaclave_sgx_sdk In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in is | 2.2% | — |
| CVE-2021-24114 | MED 5.7 | microsoft teams Microsoft Teams iOS Information Disclosure Vulnerability | 3.2% | — |
| CVE-2021-24113 | MED 5.4 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 1.5% | — |
| CVE-2021-24112 | HIGH 8.1 | microsoft .net .NET Core Remote Code Execution Vulnerability | 3.3% | — |
| CVE-2021-24111 | HIGH 7.5 | microsoft .net_framework .NET Framework Denial of Service Vulnerability | 3.8% | — |
| CVE-2021-24110 | HIGH 7.8 | microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-24109 | MED 6.8 | microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2021-24108 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-24107 | MED 5.5 | microsoft windows_10 Windows Event Tracing Information Disclosure Vulnerability | 1.0% | — |
| CVE-2021-24106 | MED 5.5 | microsoft windows_10 Windows DirectX Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-24105 | HIGH 8.4 | microsoft package_manager_configurations <p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package into a package manager's repository which can be retrieved and used during development, build, and release processes. This insertion could le | 2.4% | — |