IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.855 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-28336 HIGH 8.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 2.3%
CVE-2021-28335 HIGH 8.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 2.3%
CVE-2021-28334 HIGH 8.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 2.3%
CVE-2021-28333 HIGH 8.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 2.5%
CVE-2021-28332 HIGH 8.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 2.3%
CVE-2021-28331 HIGH 8.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 2.3%
CVE-2021-28330 HIGH 8.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 2.3%
CVE-2021-28329 HIGH 8.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 2.3%
CVE-2021-28327 HIGH 8.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 2.5%
CVE-2021-27891 HIGH 8.8 ssh tectia_client SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected. 1.0%
CVE-2021-27644 HIGH 8.8 apache dolphinscheduler In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password) 1.9%
CVE-2021-27194 HIGH 8.8 netop vision_pro Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login usernames and passwords. 0.4%
CVE-2021-27085 HIGH 8.8 microsoft internet_explorer Internet Explorer Remote Code Execution Vulnerability 5.4%
CVE-2021-27076 HIGH 8.8 microsoft business_productivity_servers Microsoft SharePoint Server Remote Code Execution Vulnerability 14.4%
CVE-2021-27068 HIGH 8.8 microsoft visual_studio_2019 Visual Studio Remote Code Execution Vulnerability 53.6%
CVE-2021-26919 HIGH 8.8 apache druid Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissions to set up lookups or submit ingestion tasks. The MySQL JDBC driver supports certain properties, which, if le 22.6%
CVE-2021-26876 HIGH 8.8 microsoft windows_10 OpenType Font Parsing Remote Code Execution Vulnerability 2.7%
CVE-2021-26865 HIGH 8.8 microsoft windows_10 Windows Container Execution Agent Elevation of Privilege Vulnerability 1.1%
CVE-2021-26828 HIGH 8.8 scadabr scadabr OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm. 39.4%
CVE-2021-26644 HIGH 8.8 mangboard mangboard_wp SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is runni 0.9%
CVE-2021-26642 HIGH 8.8 xpressengine xpressengine When uploading an image file to a bulletin board developed with XpressEngine, a vulnerability in which an arbitrary file can be uploaded due to insufficient verification of the file. A remote attacker can use this vulnerability to execute arbitrary code on the 1.2%
CVE-2021-26636 HIGH 8.8 maxb maxboard Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to information exposure and privilege escalation. 1.4%
CVE-2021-26629 HIGH 8.8 tobesoft xplatform A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..\’. 1.5%
CVE-2021-26625 HIGH 8.8 tobesoft nexacro Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers 0.6%
CVE-2021-26608 HIGH 8.8 handysoft hshell An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash. 0.6%