IT
56.560 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

CVE Tracker

56.560 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2021-28550 HIGH 8.8 adobe acrobat Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary c 52.0%
CVE-2021-28310 HIGH 7.8 microsoft windows_10_1803 Win32k Elevation of Privilege Vulnerability 8.3%
CVE-2021-27085 HIGH 8.8 microsoft internet_explorer Internet Explorer Remote Code Execution Vulnerability 3.7%
CVE-2021-27065 HIGH 7.8 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 99.9%
CVE-2021-27059 HIGH 7.6 microsoft office Microsoft Office Remote Code Execution Vulnerability 3.2%
CVE-2021-26858 HIGH 7.8 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 89.5%
CVE-2021-26857 HIGH 7.8 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 94.0%
CVE-2021-26855 CRIT 9.1 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 100.0%
CVE-2021-26411 HIGH 8.8 ransomware microsoft edge Internet Explorer Memory Corruption Vulnerability 80.7%
CVE-2021-22986 CRIT 9.8 ransomware f5 big-ip_access_policy_manager On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote 99.9%
CVE-2021-22005 CRIT 9.8 ransomware vmware cloud_foundation The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file. 100.0%
CVE-2021-21985 CRIT 9.8 ransomware vmware cloud_foundation The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this 100.0%
CVE-2021-21972 CRIT 9.8 ransomware vmware cloud_foundation The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system t 99.5%
CVE-2021-21017 HIGH 8.8 adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve 86.3%
CVE-2021-20023 MED 4.9 ransomware sonicwall email_security SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. 50.2%
CVE-2021-20022 HIGH 7.2 ransomware sonicwall email_security SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. 16.5%
CVE-2021-20021 CRIT 9.8 ransomware sonicwall email_security A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. 83.4%
CVE-2021-1732 HIGH 7.8 ransomware microsoft windows_10_1803 Windows Win32k Elevation of Privilege Vulnerability 77.8%
CVE-2021-1675 HIGH 7.8 ransomware microsoft windows_10_1507 Windows Print Spooler Remote Code Execution Vulnerability 84.8%
CVE-2021-1647 HIGH 7.8 microsoft security_essentials Microsoft Defender Remote Code Execution Vulnerability 39.4%
CVE-2021-1498 CRIT 9.8 cisco hyperflex_hx_data_platform Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Deta 100.0%
CVE-2021-1497 CRIT 9.8 cisco hyperflex_hx_data_platform Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Deta 99.9%
CVE-2020-8196 MED 4.3 citrix application_delivery_controller_firmware Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privil 26.3%
CVE-2020-8195 MED 6.5 citrix application_delivery_controller_firmware Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low priv 33.3%
CVE-2020-8193 MED 6.5 citrix application_delivery_controller_firmware Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints. 88.4%