56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.855 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-26411 | HIGH 8.8 | ransomware microsoft edge Internet Explorer Memory Corruption Vulnerability | 80.8% | |
| CVE-2021-26097 | HIGH 8.8 | fortinet fortisandbox An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6 may allow an authenticated attacker with access to the web GUI to execute unauthorized code or | 1.2% | — |
| CVE-2021-25646 | HIGH 8.8 | apache druid Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possibl | 99.0% | — |
| CVE-2021-25642 | HIGH 8.8 | apache hadoop ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users shou | 2.2% | — |
| CVE-2021-25265 | HIGH 8.8 | sophos connect A malicious website could execute code remotely in Sophos Connect Client before version 2.1. | 1.8% | — |
| CVE-2021-24093 | HIGH 8.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 43.8% | — |
| CVE-2021-24088 | HIGH 8.8 | microsoft windows_10 Windows Local Spooler Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-24072 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-24066 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Remote Code Execution Vulnerability | 5.9% | — |
| CVE-2021-24013 | HIGH 8.8 | fortinet fortimail Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and data via specifically crafted web requests. | 1.1% | — |
| CVE-2021-23040 | HIGH 8.8 | f5 big-ip_advanced_firewall_manager On BIG-IP AFM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This issue is expos | 1.0% | — |
| CVE-2021-23029 | HIGH 8.8 | f5 big-ip_advanced_web_application_firewall On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request Forgery (SSRF) attacks through F5 Advanced Web Application Firewall (WAF) and the BIG-IP ASM Configuration util | 0.9% | — |
| CVE-2021-23026 | HIGH 8.8 | f5 big-ip_access_policy_manager BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x and all versions of BIG-IQ 8.x, 7.x, and 6.x are vulnerable to cross-site request forgery (CSRF) attacks through | 0.5% | — |
| CVE-2021-23025 | HIGH 8.8 | f5 big-ip_access_policy_manager On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote command execution vulnerability exists in the BIG-IP Configuration utility. Note: Software versions which have rea | 2.3% | — |
| CVE-2021-23014 | HIGH 8.8 | f5 big-ip_advanced_web_application_firewall On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for file uploads to a specific directory within the REST API which might allow Authenticated users with guest privi | 0.8% | — |
| CVE-2021-22993 | HIGH 8.8 | f5 big-ip_advanced_web_application_firewall On BIG-IP Advanced WAF and BIG-IP ASM versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, DOM-based XSS on DoS Profile properties page. Note: Software versions which have reached En | 0.9% | — |
| CVE-2021-22988 | HIGH 8.8 | f5 big-ip_access_policy_manager On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, TMUI, also referred to as the Configuration utility, has an authenticated remote command execut | 10.4% | — |
| CVE-2021-22129 | HIGH 8.8 | fortinet fortimail Multiple instances of incorrect calculation of buffer size in the Webmail and Administrative interface of FortiMail before 6.4.5 may allow an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly execute unauthorized c | 1.1% | — |
| CVE-2021-22112 | HIGH 8.8 | oracle communications_element_manager Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to h | 3.2% | — |
| CVE-2021-22057 | HIGH 8.8 | vmware workspace_one_access VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify. | 1.1% | — |
| CVE-2021-22053 | HIGH 8.8 | vmware spring_cloud_netflix Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-p | 13.0% | — |
| CVE-2021-22048 | HIGH 8.8 | vmware cloud_foundation The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a highe | 10.0% | — |
| CVE-2021-22038 | HIGH 8.8 | vmware installbuilder On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installation directory). This temporary location is not randomized and does not restrict a | 1.0% | — |
| CVE-2021-21974 | HIGH 8.8 | vmware cloud_foundation OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be ab | 45.1% | — |
| CVE-2021-21233 | HIGH 8.8 | debian debian_linux Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1.3% | — |