58.335 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.335 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-37149 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. | 2.6% | — |
| CVE-2021-37148 | HIGH 7.5 | apache traffic_server Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1. | 2.6% | — |
| CVE-2021-37147 | HIGH 7.5 | apache traffic_server Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. | 2.5% | — |
| CVE-2021-36960 | HIGH 7.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 3.3% | — |
| CVE-2021-36953 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Denial of Service Vulnerability | 5.0% | — |
| CVE-2021-36942 | HIGH 7.5 | ransomware microsoft windows_server_2004 Windows LSA Spoofing Vulnerability | 66.0% | |
| CVE-2021-36933 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 3.5% | — |
| CVE-2021-36932 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 3.5% | — |
| CVE-2021-36926 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 3.5% | — |
| CVE-2021-36160 | HIGH 7.5 | apache http_server A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive). | 62.9% | — |
| CVE-2021-36090 | HIGH 7.5 | apache commons_compress When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Com | 12.9% | — |
| CVE-2021-35517 | HIGH 7.5 | apache commons_compress When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Com | 10.6% | — |
| CVE-2021-35516 | HIGH 7.5 | apache commons_compress When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Comp | 12.4% | — |
| CVE-2021-35515 | HIGH 7.5 | apache commons_compress When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package. | 11.6% | — |
| CVE-2021-35053 | HIGH 7.5 | kaspersky endpoint_security Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable. | 2.6% | — |
| CVE-2021-34798 | HIGH 7.5 | apache http_server Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | 64.5% | — |
| CVE-2021-34797 | HIGH 7.5 | apache geode Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "jav | 2.5% | — |
| CVE-2021-34741 | HIGH 7.5 | cisco asyncos A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due | 1.3% | — |
| CVE-2021-34691 | HIGH 7.5 | idrive remotepc iDrive RemotePC before 4.0.1 on Linux allows denial of service. A remote and unauthenticated attacker can disconnect a valid user session by connecting to an ephemeral port. | 1.0% | — |
| CVE-2021-34538 | HIGH 7.5 | apache hive Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This al | 1.8% | — |
| CVE-2021-34490 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability | 3.3% | — |
| CVE-2021-34476 | HIGH 7.5 | microsoft windows_10 Bowser.sys Denial of Service Vulnerability | 3.3% | — |
| CVE-2021-34453 | HIGH 7.5 | microsoft exchange_server Microsoft Exchange Server Denial of Service Vulnerability | 2.8% | — |
| CVE-2021-34424 | HIGH 7.5 | zoom android_meeting_sdk A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Andr | 1.7% | — |
| CVE-2021-33900 | HIGH 7.5 | apache directory_studio While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiali | 0.8% | — |