56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.569 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2020-11978 | HIGH 8.8 | apache airflow An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running | 99.2% | |
| CVE-2021-22017 | MED 5.3 | vmware vcenter_server Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being acc | 49.2% | |
| CVE-2019-1579 | HIGH 8.1 | ransomware paloaltonetworks pan-os Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code. | 46.0% | |
| CVE-2019-1458 | HIGH 7.8 | ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. | 73.9% | |
| CVE-2018-13383 | MED 4.3 | ransomware fortinet fortios A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users d | 33.6% | |
| CVE-2018-13382 | CRIT 9.1 | ransomware fortinet fortios An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the passwo | 81.7% | |
| CVE-2013-3900 | MED 5.5 | microsoft windows_10_1507 Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windo | 44.6% | |
| CVE-2021-43890 | HIGH 7.1 | ransomware microsoft app_installer We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emo | 10.3% | |
| CVE-2021-44228 | CRIT 10.0 | ransomware apache log4j Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who c | 100.0% | |
| CVE-2021-44168 | LOW 3.3 | fortinet fortios A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages. | 0.9% | |
| CVE-2019-13272 | HIGH 7.8 | canonical ubuntu_linux In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent- | 52.2% | |
| CVE-2019-0193 | HIGH 7.2 | apache solr In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen | 83.5% | |
| CVE-2021-40438 | CRIT 9.0 | ransomware apache http_server A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | 100.0% | |
| CVE-2021-42321 | HIGH 8.8 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 91.7% | |
| CVE-2021-42292 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability | 43.3% | |
| CVE-2021-40449 | HIGH 7.8 | ransomware microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 74.1% | |
| CVE-2021-42013 | CRIT 9.8 | ransomware apache http_server It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories ar | 100.0% | |
| CVE-2021-41773 | CRIT 9.8 | ransomware apache http_server A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not | 100.0% | |
| CVE-2021-40444 | HIGH 8.8 | ransomware microsoft windows_10_1507 Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An at | 97.5% | |
| CVE-2021-38649 | HIGH 7.0 | microsoft azure_automation_state_configuration Open Management Infrastructure Elevation of Privilege Vulnerability | 2.9% | |
| CVE-2021-38648 | HIGH 7.8 | microsoft azure_automation_state_configuration Open Management Infrastructure Elevation of Privilege Vulnerability | 11.4% | |
| CVE-2021-38647 | CRIT 9.8 | ransomware microsoft azure_automation_state_configuration Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | 99.9% | |
| CVE-2021-38645 | HIGH 7.8 | microsoft azure_automation_state_configuration Open Management Infrastructure Elevation of Privilege Vulnerability | 2.7% | |
| CVE-2021-36955 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 4.0% | |
| CVE-2021-36948 | HIGH 7.8 | microsoft windows_10_1809 Windows Update Medic Service Elevation of Privilege Vulnerability | 26.7% |