IT
56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.832 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-3656 HIGH 8.8 fedoraproject fedora A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" 0.7%
CVE-2021-3653 HIGH 8.8 debian debian_linux A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "int_ctl" 0.4%
CVE-2021-3626 HIGH 8.8 canonical multipass The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation. 0.2%
CVE-2021-36194 HIGH 8.8 fortinet fortiweb Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests. 1.4%
CVE-2021-36186 HIGH 8.8 fortinet fortiweb A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests 1.6%
CVE-2021-36185 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests. 1.9%
CVE-2021-36184 HIGH 8.8 fortinet fortiwlm A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclosure device, users and database information via crafted HTTP requests. 1.0%
CVE-2021-36182 HIGH 8.8 fortinet fortiweb A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests 1.9%
CVE-2021-36162 HIGH 8.8 apache dubbo Apache Dubbo supports various rules to support configuration override or traffic routing (called routing in Dubbo). These rules are loaded into the configuration center (eg: Zookeeper, Nacos, ...) and retrieved by the customers when making a request in order t 2.3%
CVE-2021-36004 HIGH 8.8 adobe indesign Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability in the CoolType library. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitati 2.2%
CVE-2021-34748 HIGH 8.8 cisco intersight_virtual_appliance A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to perform a command injection attack on an affected device. This vulnerability is due to insufficient input validation. A 2.7%
CVE-2021-34735 HIGH 8.8 cisco ata_190_firmware Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affected device. For more 1.9%
CVE-2021-34710 HIGH 8.8 cisco ata_190_firmware Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affected device. For more 2.6%
CVE-2021-34535 HIGH 8.8 microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability 21.7%
CVE-2021-34527 HIGH 8.8 ransomware microsoft windows_10_1507 A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the 99.8%
CVE-2021-34525 HIGH 8.8 microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability 2.2%
CVE-2021-34508 HIGH 8.8 microsoft windows_10 Windows Kernel Remote Code Execution Vulnerability 2.2%
CVE-2021-34494 HIGH 8.8 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 4.0%
CVE-2021-34481 HIGH 8.8 microsoft windows_10 A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the 47.7%
CVE-2021-34442 HIGH 8.8 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 3.1%
CVE-2021-33780 HIGH 8.8 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 2.7%
CVE-2021-33756 HIGH 8.8 microsoft windows_10 Windows DNS Snap-in Remote Code Execution Vulnerability 2.4%
CVE-2021-33752 HIGH 8.8 microsoft windows_10 Windows DNS Snap-in Remote Code Execution Vulnerability 2.4%
CVE-2021-33750 HIGH 8.8 microsoft windows_10 Windows DNS Snap-in Remote Code Execution Vulnerability 2.4%
CVE-2021-33749 HIGH 8.8 microsoft windows_10 Windows DNS Snap-in Remote Code Execution Vulnerability 2.4%