56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.832 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-42309 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-42283 | HIGH 8.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-42275 | HIGH 8.8 | microsoft windows_10 Microsoft COM for Windows Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-4225 | HIGH 8.8 | smartypantsplugins sp_project_\&_document_manager The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking | 1.7% | — |
| CVE-2021-41971 | HIGH 8.8 | apache superset Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malicious authenticated user sends an http request with a custom URL. | 1.8% | — |
| CVE-2021-41635 | HIGH 8.8 | melag ftp_server When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system. | 2.1% | — |
| CVE-2021-4154 | HIGH 8.8 | linux linux_kernel A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a cont | 1.2% | — |
| CVE-2021-41365 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-41020 | HIGH 8.8 | fortinet fortiisolator An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to regenerate the CA certificate via the regeneration URL. | 0.6% | — |
| CVE-2021-41018 | HIGH 8.8 | fortinet fortiweb A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests. | 3.3% | — |
| CVE-2021-41017 | HIGH 8.8 | fortinet fortiweb Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow a remote authenticated attacker to execute arbitrary code or commands via specifically crafted HTTP requests. | 1.9% | — |
| CVE-2021-4093 | HIGH 8.8 | canonical ubuntu_linux A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KVM guest using SEV-ES can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT for a string I/O instruction (for | 0.4% | — |
| CVE-2021-40444 | HIGH 8.8 | ransomware microsoft windows_10_1507 Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An at | 97.5% | |
| CVE-2021-39534 | HIGH 8.8 | juniper libslax An issue was discovered in libslax through v0.22.1. slaxIsCommentStart() in slaxlexer.c has a heap-based buffer overflow. | 1.3% | — |
| CVE-2021-39533 | HIGH 8.8 | juniper libslax An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a heap-based buffer overflow. | 1.3% | — |
| CVE-2021-39531 | HIGH 8.8 | juniper libslax An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a stack-based buffer overflow. | 1.3% | — |
| CVE-2021-39236 | HIGH 8.8 | apache ozone In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user. | 2.5% | — |
| CVE-2021-39232 | HIGH 8.8 | apache ozone In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins. | 1.6% | — |
| CVE-2021-38666 | HIGH 8.8 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 13.8% | — |
| CVE-2021-36970 | HIGH 8.8 | microsoft windows_10 Windows Print Spooler Spoofing Vulnerability | 3.1% | — |
| CVE-2021-36965 | HIGH 8.8 | microsoft windows_10 Windows WLAN AutoConfig Service Remote Code Execution Vulnerability | 4.6% | — |
| CVE-2021-36954 | HIGH 8.8 | microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36947 | HIGH 8.8 | microsoft windows_10 Windows Print Spooler Remote Code Execution Vulnerability | 7.5% | — |
| CVE-2021-36936 | HIGH 8.8 | microsoft windows_10 Windows Print Spooler Remote Code Execution Vulnerability | 7.4% | — |
| CVE-2021-36741 | HIGH 8.8 | trendmicro apex_one An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must firs | 5.0% |