57.811 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.811 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-44040 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1. | 2.0% | — |
| CVE-2021-43893 | HIGH 7.5 | microsoft windows_10 Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability | 6.6% | — |
| CVE-2021-43888 | HIGH 7.5 | microsoft defender_for_iot Microsoft Defender for IoT Information Disclosure Vulnerability | 3.0% | — |
| CVE-2021-43800 | HIGH 7.5 | requarks wiki.js Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled on a Windows host. A malicious user can potentially read any file on t | 1.7% | — |
| CVE-2021-43557 | HIGH 7.5 | apache apisix The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some occasions. For insta | 12.7% | — |
| CVE-2021-43236 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability | 3.0% | — |
| CVE-2021-43233 | HIGH 7.5 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-43228 | HIGH 7.5 | microsoft windows_10 SymCrypt Denial of Service Vulnerability | 3.7% | — |
| CVE-2021-43225 | HIGH 7.5 | microsoft bot_framework_software_development_kit Bot Framework SDK Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2021-43222 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability | 3.0% | — |
| CVE-2021-43045 | HIGH 7.5 | apache avro A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to | 3.0% | — |
| CVE-2021-42717 | HIGH 7.5 | debian debian_linux ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request ca | 3.1% | — |
| CVE-2021-42340 | HIGH 7.5 | apache tomcat The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket co | 11.8% | — |
| CVE-2021-42291 | HIGH 7.5 | microsoft windows_server Active Directory Domain Services Elevation of Privilege Vulnerability | 4.2% | — |
| CVE-2021-42287 | HIGH 7.5 | ransomware microsoft windows_server_2004 Active Directory Domain Services Elevation of Privilege Vulnerability | 77.2% | |
| CVE-2021-42282 | HIGH 7.5 | microsoft windows_server Active Directory Domain Services Elevation of Privilege Vulnerability | 4.2% | — |
| CVE-2021-42278 | HIGH 7.5 | ransomware microsoft windows_server_2004 Active Directory Domain Services Elevation of Privilege Vulnerability | 73.3% | |
| CVE-2021-41832 | HIGH 7.5 | apache openoffice It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25635 for the LibreOffice advisory. | 1.3% | — |
| CVE-2021-41830 | HIGH 7.5 | apache openoffice It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25633 for the LibreOffice | 1.4% | — |
| CVE-2021-41585 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting new connections. This issue affects Apache Traffic Server 5.0.0 to 9.1.0. | 2.5% | — |
| CVE-2021-41561 | HIGH 7.5 | apache parquet_java Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions. | 3.1% | — |
| CVE-2021-41524 | HIGH 7.5 | apache http_server While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. | 25.2% | — |
| CVE-2021-41356 | HIGH 7.5 | microsoft windows_10 Windows Denial of Service Vulnerability | 3.0% | — |
| CVE-2021-41352 | HIGH 7.5 | microsoft system_center_operations_manager SCOM Information Disclosure Vulnerability | 2.9% | — |
| CVE-2021-41079 | HIGH 7.5 | apache tomcat Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loo | 7.2% | — |