IT
58.335 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.335 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-33813 HIGH 7.5 apache solr An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. 19.4% —
CVE-2021-33788 HIGH 7.5 microsoft windows_10 Windows LSA Denial of Service Vulnerability 3.3% —
CVE-2021-33785 HIGH 7.5 microsoft windows_10 Windows AF_UNIX Socket Provider Denial of Service Vulnerability 3.3% —
CVE-2021-33772 HIGH 7.5 microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability 3.3% —
CVE-2021-33742 HIGH 7.5 microsoft windows_10_1507 Windows MSHTML Platform Remote Code Execution Vulnerability 59.4%
CVE-2021-33580 HIGH 7.5 apache roller User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programmatically. 3.3% —
CVE-2021-33500 HIGH 7.5 putty putty PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. NOTE: the same attack met 2.0% —
CVE-2021-33254 HIGH 7.5 embedthis appweb An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramter to the parseUri function. 1.5% —
CVE-2021-33193 HIGH 7.5 apache http_server A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48. 46.2% —
CVE-2021-32567 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. 2.4% —
CVE-2021-32566 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. 2.5% —
CVE-2021-32565 HIGH 7.5 apache traffic_server Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. 2.1% —
CVE-2021-31976 HIGH 7.5 microsoft windows_10 Server for NFS Information Disclosure Vulnerability 3.7% —
CVE-2021-31975 HIGH 7.5 microsoft windows_10 Server for NFS Information Disclosure Vulnerability 3.7% —
CVE-2021-31974 HIGH 7.5 microsoft windows_10 Server for NFS Denial of Service Vulnerability 6.7% —
CVE-2021-31968 HIGH 7.5 microsoft windows_10 Windows Remote Desktop Services Denial of Service Vulnerability 3.2% —
CVE-2021-31958 HIGH 7.5 microsoft windows_10 Windows NTLM Elevation of Privilege Vulnerability 2.6% —
CVE-2021-31820 HIGH 7.5 octopus octopus_server In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI. 0.6% —
CVE-2021-31618 HIGH 7.5 apache http_server Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the 51.5% —
CVE-2021-31383 HIGH 7.5 juniper junos In Point to MultiPoint (P2MP) scenarios within established sessions between network or adjacent neighbors the improper use of a source to destination copy write operation combined with a Stack-based Buffer Overflow on certain specific packets processed by the 1.0% —
CVE-2021-31379 HIGH 7.5 juniper junos An Incorrect Behavior Order vulnerability in the MAP-E automatic tunneling mechanism of Juniper Networks Junos OS allows an attacker to send certain malformed IPv4 or IPv6 packets to cause a Denial of Service (DoS) to the PFE on the device which is disabled as 1.3% —
CVE-2021-31376 HIGH 7.5 juniper junos An Improper Input Validation vulnerability in Packet Forwarding Engine manager (FXPC) process of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) by sending specific DHCPv6 packets to the device and crashing the FXPC service. Con 1.0% —
CVE-2021-31374 HIGH 7.5 juniper junos On Juniper Networks Junos OS and Junos OS Evolved devices processing a specially crafted BGP UPDATE or KEEPALIVE message can lead to a routing process daemon (RPD) crash and restart, causing a Denial of Service (DoS). Continued receipt and processing of this m 1.0% —
CVE-2021-31368 HIGH 7.5 juniper junos An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks JUNOS OS allows an unauthenticated network based attacker to cause 100% CPU load and the device to become unresponsive by sending a flood of traffic to the out-of-band managem 1.1% —
CVE-2021-31353 HIGH 7.5 juniper junos An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an attacker to inject a specific BGP update, causing the routing protocol daemon (RPD) to crash and restart, leading to a Denial of Service (D 1.2% —