IT
58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.254 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2021-1649 HIGH 7.8 microsoft windows_10 Active Template Library Elevation of Privilege Vulnerability 0.8% —
CVE-2021-1648 HIGH 7.8 microsoft windows_10 Microsoft splwow64 Elevation of Privilege Vulnerability 1.2% —
CVE-2021-1646 MED 6.6 microsoft windows_10 Windows WLAN Service Elevation of Privilege Vulnerability 0.8% —
CVE-2021-1645 MED 5.0 microsoft windows_10 Windows Docker Information Disclosure Vulnerability 7.3% —
CVE-2021-1644 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 3.8% —
CVE-2021-1643 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 3.9% —
CVE-2021-1642 HIGH 7.8 microsoft windows_10 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability 0.7% —
CVE-2021-1641 MED 4.6 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 1.8% —
CVE-2021-1640 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.9% —
CVE-2021-1639 HIGH 7.0 microsoft visual_studio_2017 Visual Studio Code Remote Code Execution Vulnerability 2.1% —
CVE-2021-1638 HIGH 7.7 microsoft windows_10 Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software 1.2% —
CVE-2021-1637 MED 5.5 microsoft windows_10 Windows DNS Query Information Disclosure Vulnerability 1.2% —
CVE-2021-1636 HIGH 8.8 microsoft sql_server Microsoft SQL Elevation of Privilege Vulnerability 6.2% —
CVE-2021-1629 MED 6.1 tableau tableau_server Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users. 1.3% —
CVE-2021-1625 MED 5.8 cisco ios_xe A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic. This vulnerability exists because ICMP and UDP resp 0.9% —
CVE-2021-1624 HIGH 8.6 cisco ios_xe A vulnerability in the Rate Limiting Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization in the Cisco QuantumFlow Processor of an affected device, resulting in a denia 1.3% —
CVE-2021-1623 HIGH 7.7 cisco ios_xe A vulnerability in the Simple Network Management Protocol (SNMP) punt handling function of Cisco cBR-8 Converged Broadband Routers could allow an authenticated, remote attacker to overload a device punt path, resulting in a denial of service (DoS) condition. T 1.1% —
CVE-2021-1622 HIGH 8.6 cisco ios_xe A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause resource exhaustion, resulting in a denial of service (DoS) condition. This v 1.0% —
CVE-2021-1621 HIGH 7.4 cisco ios_xe A vulnerability in the Layer 2 punt code of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a queue wedge on an interface that receives specific Layer 2 frames, resulting in a denial of service (DoS) condition. This vulnerabili 0.4% —
CVE-2021-1620 HIGH 7.7 cisco ios A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to exhaust the free IP addresses from the assigned local pool. Th 1.1% —
CVE-2021-1619 CRIT 9.8 cisco ios_xe A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or de 1.8% —
CVE-2021-1618 MED 6.5 cisco intersight_virtual_appliance Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnerabilities are due to i 2.7% —
CVE-2021-1617 MED 6.5 cisco intersight_virtual_appliance Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnerabilities are due to i 1.5% —
CVE-2021-1616 MED 4.7 cisco ios_xe A vulnerability in the H.323 application level gateway (ALG) used by the Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass the ALG. This vulnerability is due to insufficient data valida 1.2% —
CVE-2021-1615 HIGH 8.6 cisco embedded_wireless_controller A vulnerability in the packet processing functionality of Cisco Embedded Wireless Controller (EWC) Software for Catalyst Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected AP. This vu 1.3% —