IT
58.343 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.343 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-29703 HIGH 7.5 ibm db2 Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200659. 1.7% —
CVE-2021-29702 HIGH 7.5 ibm db2 Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658. 1.9% —
CVE-2021-29694 HIGH 7.5 ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258. 0.7% —
CVE-2021-29691 HIGH 7.5 ibm security_identity_manager IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 20025 0.9% —
CVE-2021-29688 HIGH 7.5 ibm security_identity_manager IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 200102. 2.0% —
CVE-2021-29262 HIGH 7.5 apache solr When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sen 6.7% —
CVE-2021-28966 HIGH 7.5 ruby-lang ruby In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir. 57.1% —
CVE-2021-28439 HIGH 7.5 microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability 6.1% —
CVE-2021-28324 HIGH 7.5 microsoft windows_10 Windows SMB Information Disclosure Vulnerability 6.2% —
CVE-2021-28319 HIGH 7.5 microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability 9.4% —
CVE-2021-28131 HIGH 7.5 apache impala Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with access to the logs can use another authenticated user's sessions with specially 3.3% —
CVE-2021-27738 HIGH 7.5 apache kylin All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any security checks, which allowed an unauthenticated user to issue arbitrary requests, such as assigning/unassigning 2.6% —
CVE-2021-27737 HIGH 7.5 apache traffic_server Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin. 3.8% —
CVE-2021-27577 HIGH 7.5 apache traffic_server Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. 3.5% —
CVE-2021-27576 HIGH 7.5 apache openmeetings If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0 2.8% —
CVE-2021-27434 HIGH 7.5 unified-automation .net_based_opc_ua_client\/server_sdk Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow. 1.7% —
CVE-2021-27063 HIGH 7.5 microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability 6.3% —
CVE-2021-26896 HIGH 7.5 microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability 7.4% —
CVE-2021-26881 HIGH 7.5 microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 2.6% —
CVE-2021-26879 HIGH 7.5 microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability 3.6% —
CVE-2021-26690 HIGH 7.5 apache http_server Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service 65.3% —
CVE-2021-26633 HIGH 7.5 maxb maxboard SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege escalation. This vulnerabilities can be exploited by manipulating a variable with a desired value and inserting and arbitrary file. 0.9% —
CVE-2021-26605 HIGH 7.5 unidocs ezpdfreader An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication. 1.0% —
CVE-2021-26558 HIGH 7.5 apache shardingsphere-ui Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache ShardingSphere-UI versi 2.5% —
CVE-2021-26433 HIGH 7.5 microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability 3.5% —