58.343 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.343 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-29703 | HIGH 7.5 | ibm db2 Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200659. | 1.7% | — |
| CVE-2021-29702 | HIGH 7.5 | ibm db2 Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658. | 1.9% | — |
| CVE-2021-29694 | HIGH 7.5 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258. | 0.7% | — |
| CVE-2021-29691 | HIGH 7.5 | ibm security_identity_manager IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 20025 | 0.9% | — |
| CVE-2021-29688 | HIGH 7.5 | ibm security_identity_manager IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 200102. | 2.0% | — |
| CVE-2021-29262 | HIGH 7.5 | apache solr When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sen | 6.7% | — |
| CVE-2021-28966 | HIGH 7.5 | ruby-lang ruby In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir. | 57.1% | — |
| CVE-2021-28439 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability | 6.1% | — |
| CVE-2021-28324 | HIGH 7.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 6.2% | — |
| CVE-2021-28319 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability | 9.4% | — |
| CVE-2021-28131 | HIGH 7.5 | apache impala Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with access to the logs can use another authenticated user's sessions with specially | 3.3% | — |
| CVE-2021-27738 | HIGH 7.5 | apache kylin All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any security checks, which allowed an unauthenticated user to issue arbitrary requests, such as assigning/unassigning | 2.6% | — |
| CVE-2021-27737 | HIGH 7.5 | apache traffic_server Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin. | 3.8% | — |
| CVE-2021-27577 | HIGH 7.5 | apache traffic_server Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. | 3.5% | — |
| CVE-2021-27576 | HIGH 7.5 | apache openmeetings If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0 | 2.8% | — |
| CVE-2021-27434 | HIGH 7.5 | unified-automation .net_based_opc_ua_client\/server_sdk Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow. | 1.7% | — |
| CVE-2021-27063 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability | 6.3% | — |
| CVE-2021-26896 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability | 7.4% | — |
| CVE-2021-26881 | HIGH 7.5 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2021-26879 | HIGH 7.5 | microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 3.6% | — |
| CVE-2021-26690 | HIGH 7.5 | apache http_server Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service | 65.3% | — |
| CVE-2021-26633 | HIGH 7.5 | maxb maxboard SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege escalation. This vulnerabilities can be exploited by manipulating a variable with a desired value and inserting and arbitrary file. | 0.9% | — |
| CVE-2021-26605 | HIGH 7.5 | unidocs ezpdfreader An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication. | 1.0% | — |
| CVE-2021-26558 | HIGH 7.5 | apache shardingsphere-ui Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache ShardingSphere-UI versi | 2.5% | — |
| CVE-2021-26433 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 3.5% | — |