IT
56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.832 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-42309 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 2.7%
CVE-2021-42283 HIGH 8.8 microsoft windows_10 NTFS Elevation of Privilege Vulnerability 0.5%
CVE-2021-42275 HIGH 8.8 microsoft windows_10 Microsoft COM for Windows Remote Code Execution Vulnerability 2.0%
CVE-2021-4225 HIGH 8.8 smartypantsplugins sp_project_\&_document_manager The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking 1.7%
CVE-2021-41971 HIGH 8.8 apache superset Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malicious authenticated user sends an http request with a custom URL. 1.8%
CVE-2021-41635 HIGH 8.8 melag ftp_server When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system. 2.1%
CVE-2021-4154 HIGH 8.8 linux linux_kernel A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a cont 1.2%
CVE-2021-41365 HIGH 8.8 microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability 2.7%
CVE-2021-41020 HIGH 8.8 fortinet fortiisolator An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to regenerate the CA certificate via the regeneration URL. 0.6%
CVE-2021-41018 HIGH 8.8 fortinet fortiweb A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests. 3.3%
CVE-2021-41017 HIGH 8.8 fortinet fortiweb Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow a remote authenticated attacker to execute arbitrary code or commands via specifically crafted HTTP requests. 1.9%
CVE-2021-4093 HIGH 8.8 canonical ubuntu_linux A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KVM guest using SEV-ES can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT for a string I/O instruction (for 0.4%
CVE-2021-40444 HIGH 8.8 ransomware microsoft windows_10_1507 Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An at 97.5%
CVE-2021-39534 HIGH 8.8 juniper libslax An issue was discovered in libslax through v0.22.1. slaxIsCommentStart() in slaxlexer.c has a heap-based buffer overflow. 1.3%
CVE-2021-39533 HIGH 8.8 juniper libslax An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a heap-based buffer overflow. 1.3%
CVE-2021-39531 HIGH 8.8 juniper libslax An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a stack-based buffer overflow. 1.3%
CVE-2021-39236 HIGH 8.8 apache ozone In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user. 2.5%
CVE-2021-39232 HIGH 8.8 apache ozone In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins. 1.6%
CVE-2021-38666 HIGH 8.8 microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability 13.8%
CVE-2021-36970 HIGH 8.8 microsoft windows_10 Windows Print Spooler Spoofing Vulnerability 3.1%
CVE-2021-36965 HIGH 8.8 microsoft windows_10 Windows WLAN AutoConfig Service Remote Code Execution Vulnerability 4.6%
CVE-2021-36954 HIGH 8.8 microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability 0.5%
CVE-2021-36947 HIGH 8.8 microsoft windows_10 Windows Print Spooler Remote Code Execution Vulnerability 7.5%
CVE-2021-36936 HIGH 8.8 microsoft windows_10 Windows Print Spooler Remote Code Execution Vulnerability 7.4%
CVE-2021-36741 HIGH 8.8 trendmicro apex_one An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must firs 5.0%