56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.855 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-40127 | MED 5.3 | cisco sf200-24_firmware A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an unauthenticated, remote att | 1.3% | — |
| CVE-2021-40125 | MED 5.3 | cisco adaptive_security_appliance_software A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to trigger a denial of service (Do | 1.0% | — |
| CVE-2021-39086 | MED 5.3 | ibm sterling_file_gateway IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be | 0.9% | — |
| CVE-2021-39006 | MED 5.3 | ibm qradar_wincollect IBM QRadar WinCollect Agent 10.0 and 10.0.1 could allow an attacker to obtain sensitive information due to missing best practices. IBM X-Force ID: 213549. | 0.9% | — |
| CVE-2021-38981 | MED 5.3 | ibm security_guardium_key_lifecycle_manager IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IB | 1.3% | — |
| CVE-2021-38980 | MED 5.3 | ibm security_guardium_key_lifecycle_manager IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be | 1.2% | — |
| CVE-2021-38939 | MED 5.3 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains. IBM X-Force ID: 211037. | 0.8% | — |
| CVE-2021-38879 | MED 5.3 | ibm jazz_team_server IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from th | 1.1% | — |
| CVE-2021-36930 | MED 5.3 | microsoft edge Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-36187 | MED 5.3 | fortinet fortiweb A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to cause a denial of service for webserver daemon via crafted HTTP requests | 1.4% | — |
| CVE-2021-35936 | MED 5.3 | apache airflow If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server and is listening on a specific port and also binds on 0.0.0.0 by default. This logging server had no authentic | 4.0% | — |
| CVE-2021-34794 | MED 5.3 | cisco adaptive_security_appliance_software A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to q | 0.9% | — |
| CVE-2021-34787 | MED 5.3 | cisco adaptive_security_appliance A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. | 1.0% | — |
| CVE-2021-34736 | MED 5.3 | cisco unified_computing_system A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insu | 1.3% | — |
| CVE-2021-34705 | MED 5.3 | cisco ios A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured destination patterns and dial arbitrary numbers. This vulnerability is d | 1.0% | — |
| CVE-2021-34687 | MED 5.3 | idrive remotepc iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The Personal Key is transmitted over the network while only being encrypted via a s | 0.2% | — |
| CVE-2021-34519 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Server Information Disclosure Vulnerability | 6.1% | — |
| CVE-2021-34517 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1.9% | — |
| CVE-2021-34451 | MED 5.3 | microsoft office_online_server Microsoft Office Online Server Spoofing Vulnerability | 1.8% | — |
| CVE-2021-34426 | MED 5.3 | keybase keybase A vulnerability was discovered in the Keybase Client for Windows before version 5.6.0 when a user executed the "keybase git lfs-config" command on the command-line. In versions prior to 5.6.0, a malicious actor with write access to a user\'s Git repository cou | 0.2% | — |
| CVE-2021-33757 | MED 5.3 | microsoft windows_10 Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability | 3.4% | — |
| CVE-2021-33744 | MED 5.3 | microsoft windows_10 Windows Secure Kernel Mode Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2021-33190 | MED 5.3 | apache apisix_dashboard In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was used for the IP acquisition, which made i | 2.7% | — |
| CVE-2021-33037 | MED 5.3 | apache tomcat Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - To | 75.4% | — |
| CVE-2021-32785 | MED 5.3 | debian debian_linux mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. When mod_auth_openidc versions prior to 2.4.9 are configured t | 2.7% | — |