57.825 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.825 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-35053 | HIGH 7.5 | kaspersky endpoint_security Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable. | 2.6% | — |
| CVE-2021-34798 | HIGH 7.5 | apache http_server Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | 64.5% | — |
| CVE-2021-34797 | HIGH 7.5 | apache geode Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "jav | 2.5% | — |
| CVE-2021-34741 | HIGH 7.5 | cisco asyncos A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due | 1.3% | — |
| CVE-2021-34691 | HIGH 7.5 | idrive remotepc iDrive RemotePC before 4.0.1 on Linux allows denial of service. A remote and unauthenticated attacker can disconnect a valid user session by connecting to an ephemeral port. | 1.0% | — |
| CVE-2021-34538 | HIGH 7.5 | apache hive Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This al | 1.8% | — |
| CVE-2021-34490 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability | 3.3% | — |
| CVE-2021-34476 | HIGH 7.5 | microsoft windows_10 Bowser.sys Denial of Service Vulnerability | 3.3% | — |
| CVE-2021-34453 | HIGH 7.5 | microsoft exchange_server Microsoft Exchange Server Denial of Service Vulnerability | 2.8% | — |
| CVE-2021-34424 | HIGH 7.5 | zoom android_meeting_sdk A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Andr | 1.7% | — |
| CVE-2021-33900 | HIGH 7.5 | apache directory_studio While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiali | 0.8% | — |
| CVE-2021-33813 | HIGH 7.5 | apache solr An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. | 19.4% | — |
| CVE-2021-33788 | HIGH 7.5 | microsoft windows_10 Windows LSA Denial of Service Vulnerability | 3.3% | — |
| CVE-2021-33785 | HIGH 7.5 | microsoft windows_10 Windows AF_UNIX Socket Provider Denial of Service Vulnerability | 3.3% | — |
| CVE-2021-33772 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability | 3.3% | — |
| CVE-2021-33742 | HIGH 7.5 | microsoft windows_10_1507 Windows MSHTML Platform Remote Code Execution Vulnerability | 59.4% | |
| CVE-2021-33580 | HIGH 7.5 | apache roller User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programmatically. | 3.3% | — |
| CVE-2021-33500 | HIGH 7.5 | putty putty PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. NOTE: the same attack met | 2.0% | — |
| CVE-2021-33254 | HIGH 7.5 | embedthis appweb An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramter to the parseUri function. | 1.5% | — |
| CVE-2021-33193 | HIGH 7.5 | apache http_server A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48. | 46.2% | — |
| CVE-2021-32567 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. | 2.4% | — |
| CVE-2021-32566 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. | 2.5% | — |
| CVE-2021-32565 | HIGH 7.5 | apache traffic_server Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. | 2.1% | — |
| CVE-2021-31976 | HIGH 7.5 | microsoft windows_10 Server for NFS Information Disclosure Vulnerability | 3.7% | — |
| CVE-2021-31975 | HIGH 7.5 | microsoft windows_10 Server for NFS Information Disclosure Vulnerability | 3.7% | — |