58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2021-21384 | MED 6.3 | shescape_project shescape shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to defend against shell injection may still be vulnerable against shell injection if the attacker manages to insert a into the payload. For an e | 0.6% | — |
| CVE-2021-21351 | MED 5.4 | apache activemq XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. | 82.1% | — |
| CVE-2021-21350 | MED 5.3 | apache activemq XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, w | 15.2% | — |
| CVE-2021-21349 | MED 6.1 | apache activemq XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the | 46.8% | — |
| CVE-2021-21348 | MED 5.3 | apache activemq XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who | 13.8% | — |
| CVE-2021-21347 | MED 6.1 | apache activemq XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input st | 14.3% | — |
| CVE-2021-21346 | MED 6.1 | apache activemq XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input st | 76.4% | — |
| CVE-2021-21345 | MED 5.8 | apache activemq XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed inpu | 72.3% | — |
| CVE-2021-21344 | MED 5.3 | apache activemq XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input st | 76.0% | — |
| CVE-2021-21343 | MED 5.3 | apache activemq XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream create | 46.7% | — |
| CVE-2021-21342 | MED 5.3 | apache activemq XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream create | 50.0% | — |
| CVE-2021-21341 | HIGH 7.5 | apache activemq XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such | 77.8% | — |
| CVE-2021-21295 | MED 5.9 | apache kudu Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that | 18.9% | — |
| CVE-2021-21292 | MED 5.5 | traccar traccar Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path vulnerability. Only Windows versions are impacted. Attacker needs write access to the filesystem on the host machine. If Java path includes a | 0.4% | — |
| CVE-2021-21233 | HIGH 8.8 | debian debian_linux Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1.3% | — |
| CVE-2021-21196 | HIGH 8.8 | fedoraproject fedora Heap buffer overflow in TabStrip in Google Chrome on Windows prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1.3% | — |
| CVE-2021-21179 | HIGH 8.8 | debian debian_linux Use after free in Network Internals in Google Chrome on Linux prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1.4% | — |
| CVE-2021-21178 | MED 6.5 | debian debian_linux Inappropriate implementation in Compositing in Google Chrome on Linux and Windows prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | 1.6% | — |
| CVE-2021-21172 | HIGH 8.1 | debian debian_linux Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | 1.7% | — |
| CVE-2021-21157 | HIGH 8.8 | fedoraproject fedora Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 9.5% | — |
| CVE-2021-21155 | CRIT 9.6 | fedoraproject fedora Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | 1.3% | — |
| CVE-2021-21153 | HIGH 8.8 | fedoraproject fedora Stack buffer overflow in GPU Process in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | 1.3% | — |
| CVE-2021-21152 | HIGH 8.8 | fedoraproject fedora Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1.3% | — |
| CVE-2021-21150 | CRIT 9.6 | fedoraproject fedora Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | 1.2% | — |
| CVE-2021-21149 | HIGH 8.8 | fedoraproject fedora Stack buffer overflow in Data Transfer in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. | 1.5% | — |