56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.832 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-33036 | HIGH 8.8 | apache hadoop In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher. | 3.8% | — |
| CVE-2021-32603 | HIGH 8.8 | fortinet fortianalyzer A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and servic | 0.7% | — |
| CVE-2021-32462 | HIGH 8.8 | trendmicro password_manager Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerability which could allow an unprivileged client to manipulate the registry and escalate privileges to SYSTEM on aff | 5.2% | — |
| CVE-2021-31982 | HIGH 8.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2021-31385 | HIGH 8.8 | juniper junos An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in J-Web of Juniper Networks Junos OS allows any low-privileged authenticated attacker to elevate their privileges to root. This issue affects: Juniper Networks Jun | 1.5% | — |
| CVE-2021-31372 | HIGH 8.8 | juniper junos An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated J-Web attacker to escalate their privileges to root over the target device. This issue affects: Juniper Networks Junos OS All versions prior to 18.3 | 1.2% | — |
| CVE-2021-31194 | HIGH 8.8 | microsoft windows_10 OLE Automation Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-31181 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Remote Code Execution Vulnerability | 30.0% | — |
| CVE-2021-30624 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30624 Use after free in Autofill | 4.1% | — |
| CVE-2021-30623 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30623 Use after free in Bookmarks | 4.0% | — |
| CVE-2021-30622 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30622 Use after free in WebApp Installs | 4.1% | — |
| CVE-2021-30620 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink | 4.1% | — |
| CVE-2021-30618 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30618 Inappropriate implementation in DevTools | 4.1% | — |
| CVE-2021-30616 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30616 Use after free in Media | 4.2% | — |
| CVE-2021-30614 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip | 4.5% | — |
| CVE-2021-30613 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30613 Use after free in Base internals | 4.1% | — |
| CVE-2021-30612 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30612 Use after free in WebRTC | 2.8% | — |
| CVE-2021-30611 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30611 Use after free in WebRTC | 2.8% | — |
| CVE-2021-30610 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30610 Use after free in Extensions API | 4.1% | — |
| CVE-2021-30609 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30609 Use after free in Sign-In | 4.2% | — |
| CVE-2021-30608 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30608 Use after free in Web Share | 4.1% | — |
| CVE-2021-30607 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30607 Use after free in Permissions | 4.1% | — |
| CVE-2021-30606 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30606 Use after free in Blink | 4.1% | — |
| CVE-2021-3058 | HIGH 8.8 | paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 vers | 1.6% | — |
| CVE-2021-30565 | HIGH 8.8 | fedoraproject fedora Out of bounds write in Tab Groups in Google Chrome on Linux and ChromeOS prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page. | 1.9% | — |