IT
58.335 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.335 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-37149 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. 2.6% —
CVE-2021-37148 HIGH 7.5 apache traffic_server Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1. 2.6% —
CVE-2021-37147 HIGH 7.5 apache traffic_server Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. 2.5% —
CVE-2021-36960 HIGH 7.5 microsoft windows_10 Windows SMB Information Disclosure Vulnerability 3.3% —
CVE-2021-36953 HIGH 7.5 microsoft windows_10 Windows TCP/IP Denial of Service Vulnerability 5.0% —
CVE-2021-36942 HIGH 7.5 ransomware microsoft windows_server_2004 Windows LSA Spoofing Vulnerability 66.0%
CVE-2021-36933 HIGH 7.5 microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability 3.5% —
CVE-2021-36932 HIGH 7.5 microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability 3.5% —
CVE-2021-36926 HIGH 7.5 microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability 3.5% —
CVE-2021-36160 HIGH 7.5 apache http_server A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive). 62.9% —
CVE-2021-36090 HIGH 7.5 apache commons_compress When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Com 12.9% —
CVE-2021-35517 HIGH 7.5 apache commons_compress When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Com 10.6% —
CVE-2021-35516 HIGH 7.5 apache commons_compress When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Comp 12.4% —
CVE-2021-35515 HIGH 7.5 apache commons_compress When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package. 11.6% —
CVE-2021-35053 HIGH 7.5 kaspersky endpoint_security Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable. 2.6% —
CVE-2021-34798 HIGH 7.5 apache http_server Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. 64.5% —
CVE-2021-34797 HIGH 7.5 apache geode Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "jav 2.5% —
CVE-2021-34741 HIGH 7.5 cisco asyncos A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due 1.3% —
CVE-2021-34691 HIGH 7.5 idrive remotepc iDrive RemotePC before 4.0.1 on Linux allows denial of service. A remote and unauthenticated attacker can disconnect a valid user session by connecting to an ephemeral port. 1.0% —
CVE-2021-34538 HIGH 7.5 apache hive Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This al 1.8% —
CVE-2021-34490 HIGH 7.5 microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability 3.3% —
CVE-2021-34476 HIGH 7.5 microsoft windows_10 Bowser.sys Denial of Service Vulnerability 3.3% —
CVE-2021-34453 HIGH 7.5 microsoft exchange_server Microsoft Exchange Server Denial of Service Vulnerability 2.8% —
CVE-2021-34424 HIGH 7.5 zoom android_meeting_sdk A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Andr 1.7% —
CVE-2021-33900 HIGH 7.5 apache directory_studio While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiali 0.8% —