56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.832 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-3656 | HIGH 8.8 | fedoraproject fedora A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" | 0.7% | — |
| CVE-2021-3653 | HIGH 8.8 | debian debian_linux A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "int_ctl" | 0.4% | — |
| CVE-2021-3626 | HIGH 8.8 | canonical multipass The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation. | 0.2% | — |
| CVE-2021-36194 | HIGH 8.8 | fortinet fortiweb Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests. | 1.4% | — |
| CVE-2021-36186 | HIGH 8.8 | fortinet fortiweb A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests | 1.6% | — |
| CVE-2021-36185 | HIGH 8.8 | fortinet fortiwlm A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests. | 1.9% | — |
| CVE-2021-36184 | HIGH 8.8 | fortinet fortiwlm A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclosure device, users and database information via crafted HTTP requests. | 1.0% | — |
| CVE-2021-36182 | HIGH 8.8 | fortinet fortiweb A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests | 1.9% | — |
| CVE-2021-36162 | HIGH 8.8 | apache dubbo Apache Dubbo supports various rules to support configuration override or traffic routing (called routing in Dubbo). These rules are loaded into the configuration center (eg: Zookeeper, Nacos, ...) and retrieved by the customers when making a request in order t | 2.3% | — |
| CVE-2021-36004 | HIGH 8.8 | adobe indesign Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability in the CoolType library. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitati | 2.2% | — |
| CVE-2021-34748 | HIGH 8.8 | cisco intersight_virtual_appliance A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to perform a command injection attack on an affected device. This vulnerability is due to insufficient input validation. A | 2.7% | — |
| CVE-2021-34735 | HIGH 8.8 | cisco ata_190_firmware Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affected device. For more | 1.9% | — |
| CVE-2021-34710 | HIGH 8.8 | cisco ata_190_firmware Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affected device. For more | 2.6% | — |
| CVE-2021-34535 | HIGH 8.8 | microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability | 21.7% | — |
| CVE-2021-34527 | HIGH 8.8 | ransomware microsoft windows_10_1507 A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the | 99.8% | |
| CVE-2021-34525 | HIGH 8.8 | microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-34508 | HIGH 8.8 | microsoft windows_10 Windows Kernel Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-34494 | HIGH 8.8 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 4.0% | — |
| CVE-2021-34481 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the | 47.7% | — |
| CVE-2021-34442 | HIGH 8.8 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2021-33780 | HIGH 8.8 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-33756 | HIGH 8.8 | microsoft windows_10 Windows DNS Snap-in Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-33752 | HIGH 8.8 | microsoft windows_10 Windows DNS Snap-in Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-33750 | HIGH 8.8 | microsoft windows_10 Windows DNS Snap-in Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-33749 | HIGH 8.8 | microsoft windows_10 Windows DNS Snap-in Remote Code Execution Vulnerability | 2.4% | — |