IT
56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.960 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-42310 HIGH 8.1 microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability 2.0%
CVE-2021-42306 HIGH 8.1 microsoft azure_active_directory An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential  on an Azure AD Application or Service Principal (which is not recommended). This vulner 3.1%
CVE-2021-41766 HIGH 8.1 apache karaf Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implementation 2.0%
CVE-2021-41344 HIGH 8.1 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 6.5%
CVE-2021-40487 HIGH 8.1 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 48.2%
CVE-2021-40331 HIGH 8.1 apache ranger An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled This issue af 0.9%
CVE-2021-39057 HIGH 8.1 ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other at 0.5%
CVE-2021-38941 HIGH 8.1 ibm cloud_pak_for_multicloud_management_monitoring IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable to host information leakage or destruction if unauthorized access to these containers could execute arbitrary commands. IBM X-Force ID: 21104 0.9%
CVE-2021-38161 HIGH 8.1 apache traffic_server Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8. 1.9%
CVE-2021-36180 HIGH 8.1 fortinet fortiweb Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.5 and below may allow an authenticated attacker to execute unauthorized code or commands via 1.1%
CVE-2021-36171 HIGH 8.1 fortinet fortiportal The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predict parts of or the whole newly generated password within a given time frame. 1.2%
CVE-2021-34762 HIGH 8.1 cisco firepower_management_center_virtual_appliance A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device crede 2.0%
CVE-2021-34739 HIGH 8.1 cisco cbs250-16p-2g_firmware A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized access to the web-based management interface o 1.7%
CVE-2021-34718 HIGH 8.1 cisco ios_xr A vulnerability in the SSH Server process of Cisco IOS XR Software could allow an authenticated, remote attacker to overwrite and read arbitrary files on the local device. This vulnerability is due to insufficient input validation of arguments that are supplie 1.6%
CVE-2021-34551 HIGH 8.1 fedoraproject fedora PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname. 2.8%
CVE-2021-34524 HIGH 8.1 microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability 3.6%
CVE-2021-34520 HIGH 8.1 microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability 4.4%
CVE-2021-34492 HIGH 8.1 microsoft windows_10 Windows Certificate Spoofing Vulnerability 2.4%
CVE-2021-33786 HIGH 8.1 microsoft windows_server_2008 Windows LSA Security Feature Bypass Vulnerability 2.1%
CVE-2021-33781 HIGH 8.1 microsoft windows_10 Azure AD Security Feature Bypass Vulnerability 2.4%
CVE-2021-33779 HIGH 8.1 microsoft windows_server_2016 Windows AD FS Security Feature Bypass Vulnerability 2.4%
CVE-2021-33113 HIGH 8.1 intel ac_1550_firmware Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access. 0.7%
CVE-2021-32589 HIGH 8.1 fortinet fortianalyzer A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.2.10 and below, version 5.0.12 and below and FortiA 8.7%
CVE-2021-31980 HIGH 8.1 microsoft intune_management_extension Microsoft Intune Management Extension Remote Code Execution Vulnerability 2.5%
CVE-2021-3062 HIGH 8.1 paloaltonetworks pan-os An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS. Exploitation of this 0.7%