IT
57.811 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.811 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-44040 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1. 2.0%
CVE-2021-43893 HIGH 7.5 microsoft windows_10 Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability 6.6%
CVE-2021-43888 HIGH 7.5 microsoft defender_for_iot Microsoft Defender for IoT Information Disclosure Vulnerability 3.0%
CVE-2021-43800 HIGH 7.5 requarks wiki.js Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled on a Windows host. A malicious user can potentially read any file on t 1.7%
CVE-2021-43557 HIGH 7.5 apache apisix The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some occasions. For insta 12.7%
CVE-2021-43236 HIGH 7.5 microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability 3.0%
CVE-2021-43233 HIGH 7.5 microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability 2.2%
CVE-2021-43228 HIGH 7.5 microsoft windows_10 SymCrypt Denial of Service Vulnerability 3.7%
CVE-2021-43225 HIGH 7.5 microsoft bot_framework_software_development_kit Bot Framework SDK Remote Code Execution Vulnerability 2.8%
CVE-2021-43222 HIGH 7.5 microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability 3.0%
CVE-2021-43045 HIGH 7.5 apache avro A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to 3.0%
CVE-2021-42717 HIGH 7.5 debian debian_linux ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request ca 3.1%
CVE-2021-42340 HIGH 7.5 apache tomcat The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket co 11.8%
CVE-2021-42291 HIGH 7.5 microsoft windows_server Active Directory Domain Services Elevation of Privilege Vulnerability 4.2%
CVE-2021-42287 HIGH 7.5 ransomware microsoft windows_server_2004 Active Directory Domain Services Elevation of Privilege Vulnerability 77.2%
CVE-2021-42282 HIGH 7.5 microsoft windows_server Active Directory Domain Services Elevation of Privilege Vulnerability 4.2%
CVE-2021-42278 HIGH 7.5 ransomware microsoft windows_server_2004 Active Directory Domain Services Elevation of Privilege Vulnerability 73.3%
CVE-2021-41832 HIGH 7.5 apache openoffice It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25635 for the LibreOffice advisory. 1.3%
CVE-2021-41830 HIGH 7.5 apache openoffice It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25633 for the LibreOffice 1.4%
CVE-2021-41585 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting new connections. This issue affects Apache Traffic Server 5.0.0 to 9.1.0. 2.5%
CVE-2021-41561 HIGH 7.5 apache parquet_java Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions. 3.1%
CVE-2021-41524 HIGH 7.5 apache http_server While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. 25.2%
CVE-2021-41356 HIGH 7.5 microsoft windows_10 Windows Denial of Service Vulnerability 3.0%
CVE-2021-41352 HIGH 7.5 microsoft system_center_operations_manager SCOM Information Disclosure Vulnerability 2.9%
CVE-2021-41079 HIGH 7.5 apache tomcat Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loo 7.2%