57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-22003 | HIGH 7.5 | vmware cloud_foundation VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based | 1.0% | — |
| CVE-2021-21995 | HIGH 7.5 | vmware cloud_foundation OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 on ESXi may be able to trigger a heap out-of-bounds read in OpenSLP service resulting in a denial-of-service co | 1.0% | — |
| CVE-2021-21980 | HIGH 7.5 | vmware cloud_foundation The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information. | 4.6% | — |
| CVE-2021-21975 | HIGH 7.5 | ransomware vmware cloud_foundation Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credent | 78.3% | |
| CVE-2021-21501 | HIGH 7.5 | apache servicecomb Improper configuration will cause ServiceComb ServiceCenter Directory Traversal problem in ServcieCenter 1.x.x versions and fixed in 2.0.0. | 4.4% | — |
| CVE-2021-21341 | HIGH 7.5 | apache activemq XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such | 77.8% | — |
| CVE-2021-20442 | HIGH 7.5 | ibm security_verify_bridge IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196618. | 1.0% | — |
| CVE-2021-20427 | HIGH 7.5 | ibm security_guardium IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314. | 1.3% | — |
| CVE-2021-20419 | HIGH 7.5 | ibm security_guardium IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280. | 0.7% | — |
| CVE-2021-20412 | HIGH 7.5 | ibm security_verify_information_queue IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM | 0.9% | — |
| CVE-2021-20400 | HIGH 7.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074. | 0.7% | — |
| CVE-2021-20373 | HIGH 7.5 | ibm db2 IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521. | 1.5% | — |
| CVE-2021-20354 | HIGH 7.5 | ibm websphere_application_server IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883 | 4.1% | — |
| CVE-2021-20337 | HIGH 7.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 194448. | 0.7% | — |
| CVE-2021-1734 | HIGH 7.5 | microsoft windows_10 Windows Remote Procedure Call Information Disclosure Vulnerability | 3.6% | — |
| CVE-2021-1723 | HIGH 7.5 | fedoraproject fedora ASP.NET Core and Visual Studio Denial of Service Vulnerability | 4.9% | — |
| CVE-2021-1694 | HIGH 7.5 | microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability | 3.2% | — |
| CVE-2021-1594 | HIGH 7.5 | cisco identity_services_engine A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a command injection attack and elevate privileges to root. This vulnerability is due to insufficient input validation for specifi | 1.4% | — |
| CVE-2021-1585 | HIGH 7.5 | cisco adaptive_security_device_manager A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of proper signature verification for speci | 20.0% | — |
| CVE-2021-1513 | HIGH 7.5 | cisco catalyst_sd-wan_manager A vulnerability in the vDaemon process of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient handling of malformed packe | 1.5% | — |
| CVE-2021-1511 | HIGH 7.5 | cisco vedge_1000_firmware Multiple vulnerabilities in Cisco SD-WAN vEdge Software could allow an attacker to execute arbitrary code as the root user or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details sec | 1.0% | — |
| CVE-2021-1510 | HIGH 7.5 | cisco vedge_1000_firmware Multiple vulnerabilities in Cisco SD-WAN vEdge Software could allow an attacker to execute arbitrary code as the root user or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details sec | 1.2% | — |
| CVE-2021-1509 | HIGH 7.5 | cisco vedge_1000_firmware Multiple vulnerabilities in Cisco SD-WAN vEdge Software could allow an attacker to execute arbitrary code as the root user or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details sec | 1.2% | — |
| CVE-2021-1437 | HIGH 7.5 | cisco aironet_access_point_software A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial F | 1.5% | — |
| CVE-2021-1431 | HIGH 7.5 | cisco ios_xe A vulnerability in the vDaemon process of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, resulting a denial of service (DoS) condition. This vulnerability is due to insufficient handling of malformed p | 1.6% | — |