56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.855 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-28336 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28335 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28334 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28333 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-28332 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28331 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28330 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28329 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28327 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-27891 | HIGH 8.8 | ssh tectia_client SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected. | 1.0% | — |
| CVE-2021-27644 | HIGH 8.8 | apache dolphinscheduler In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password) | 1.9% | — |
| CVE-2021-27194 | HIGH 8.8 | netop vision_pro Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login usernames and passwords. | 0.4% | — |
| CVE-2021-27085 | HIGH 8.8 | microsoft internet_explorer Internet Explorer Remote Code Execution Vulnerability | 5.4% | |
| CVE-2021-27076 | HIGH 8.8 | microsoft business_productivity_servers Microsoft SharePoint Server Remote Code Execution Vulnerability | 14.4% | — |
| CVE-2021-27068 | HIGH 8.8 | microsoft visual_studio_2019 Visual Studio Remote Code Execution Vulnerability | 53.6% | — |
| CVE-2021-26919 | HIGH 8.8 | apache druid Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissions to set up lookups or submit ingestion tasks. The MySQL JDBC driver supports certain properties, which, if le | 22.6% | — |
| CVE-2021-26876 | HIGH 8.8 | microsoft windows_10 OpenType Font Parsing Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-26865 | HIGH 8.8 | microsoft windows_10 Windows Container Execution Agent Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-26828 | HIGH 8.8 | scadabr scadabr OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm. | 39.4% | |
| CVE-2021-26644 | HIGH 8.8 | mangboard mangboard_wp SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is runni | 0.9% | — |
| CVE-2021-26642 | HIGH 8.8 | xpressengine xpressengine When uploading an image file to a bulletin board developed with XpressEngine, a vulnerability in which an arbitrary file can be uploaded due to insufficient verification of the file. A remote attacker can use this vulnerability to execute arbitrary code on the | 1.2% | — |
| CVE-2021-26636 | HIGH 8.8 | maxb maxboard Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to information exposure and privilege escalation. | 1.4% | — |
| CVE-2021-26629 | HIGH 8.8 | tobesoft xplatform A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..\’. | 1.5% | — |
| CVE-2021-26625 | HIGH 8.8 | tobesoft nexacro Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers | 0.6% | — |
| CVE-2021-26608 | HIGH 8.8 | handysoft hshell An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash. | 0.6% | — |