57.859 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.859 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-33772 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability | 3.3% | — |
| CVE-2021-33742 | HIGH 7.5 | microsoft windows_10_1507 Windows MSHTML Platform Remote Code Execution Vulnerability | 59.4% | |
| CVE-2021-33580 | HIGH 7.5 | apache roller User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programmatically. | 3.3% | — |
| CVE-2021-33500 | HIGH 7.5 | putty putty PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. NOTE: the same attack met | 2.0% | — |
| CVE-2021-33254 | HIGH 7.5 | embedthis appweb An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramter to the parseUri function. | 1.5% | — |
| CVE-2021-33193 | HIGH 7.5 | apache http_server A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48. | 46.2% | — |
| CVE-2021-32567 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. | 2.4% | — |
| CVE-2021-32566 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. | 2.5% | — |
| CVE-2021-32565 | HIGH 7.5 | apache traffic_server Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. | 2.1% | — |
| CVE-2021-31976 | HIGH 7.5 | microsoft windows_10 Server for NFS Information Disclosure Vulnerability | 3.7% | — |
| CVE-2021-31975 | HIGH 7.5 | microsoft windows_10 Server for NFS Information Disclosure Vulnerability | 3.7% | — |
| CVE-2021-31974 | HIGH 7.5 | microsoft windows_10 Server for NFS Denial of Service Vulnerability | 6.7% | — |
| CVE-2021-31968 | HIGH 7.5 | microsoft windows_10 Windows Remote Desktop Services Denial of Service Vulnerability | 3.2% | — |
| CVE-2021-31958 | HIGH 7.5 | microsoft windows_10 Windows NTLM Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2021-31820 | HIGH 7.5 | octopus octopus_server In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI. | 0.6% | — |
| CVE-2021-31618 | HIGH 7.5 | apache http_server Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the | 51.5% | — |
| CVE-2021-31383 | HIGH 7.5 | juniper junos In Point to MultiPoint (P2MP) scenarios within established sessions between network or adjacent neighbors the improper use of a source to destination copy write operation combined with a Stack-based Buffer Overflow on certain specific packets processed by the | 1.0% | — |
| CVE-2021-31379 | HIGH 7.5 | juniper junos An Incorrect Behavior Order vulnerability in the MAP-E automatic tunneling mechanism of Juniper Networks Junos OS allows an attacker to send certain malformed IPv4 or IPv6 packets to cause a Denial of Service (DoS) to the PFE on the device which is disabled as | 1.3% | — |
| CVE-2021-31376 | HIGH 7.5 | juniper junos An Improper Input Validation vulnerability in Packet Forwarding Engine manager (FXPC) process of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) by sending specific DHCPv6 packets to the device and crashing the FXPC service. Con | 1.0% | — |
| CVE-2021-31374 | HIGH 7.5 | juniper junos On Juniper Networks Junos OS and Junos OS Evolved devices processing a specially crafted BGP UPDATE or KEEPALIVE message can lead to a routing process daemon (RPD) crash and restart, causing a Denial of Service (DoS). Continued receipt and processing of this m | 1.0% | — |
| CVE-2021-31368 | HIGH 7.5 | juniper junos An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks JUNOS OS allows an unauthenticated network based attacker to cause 100% CPU load and the device to become unresponsive by sending a flood of traffic to the out-of-band managem | 1.1% | — |
| CVE-2021-31353 | HIGH 7.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an attacker to inject a specific BGP update, causing the routing protocol daemon (RPD) to crash and restart, leading to a Denial of Service (D | 1.2% | — |
| CVE-2021-31351 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions in packet processing on the MS-MPC/MS-MIC utilized by Juniper Networks Junos OS allows a malicious attacker to send a specific packet, triggering the MS-MPC/MS-MIC to reset, causing a Denial of Service (D | 1.0% | — |
| CVE-2021-31350 | HIGH 7.5 | juniper junos An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on Juniper Networks Junos OS and Junos OS Evolved, allows a network-based, low-privileged authenticated attacker to perform operations as root | 0.9% | — |
| CVE-2021-31183 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability | 3.8% | — |