56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-42310 | HIGH 8.1 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-42306 | HIGH 8.1 | microsoft azure_active_directory An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulner | 3.1% | — |
| CVE-2021-41766 | HIGH 8.1 | apache karaf Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implementation | 2.0% | — |
| CVE-2021-41344 | HIGH 8.1 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 6.5% | — |
| CVE-2021-40487 | HIGH 8.1 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 48.2% | — |
| CVE-2021-40331 | HIGH 8.1 | apache ranger An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled This issue af | 0.9% | — |
| CVE-2021-39057 | HIGH 8.1 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other at | 0.5% | — |
| CVE-2021-38941 | HIGH 8.1 | ibm cloud_pak_for_multicloud_management_monitoring IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable to host information leakage or destruction if unauthorized access to these containers could execute arbitrary commands. IBM X-Force ID: 21104 | 0.9% | — |
| CVE-2021-38161 | HIGH 8.1 | apache traffic_server Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8. | 1.9% | — |
| CVE-2021-36180 | HIGH 8.1 | fortinet fortiweb Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.5 and below may allow an authenticated attacker to execute unauthorized code or commands via | 1.1% | — |
| CVE-2021-36171 | HIGH 8.1 | fortinet fortiportal The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predict parts of or the whole newly generated password within a given time frame. | 1.2% | — |
| CVE-2021-34762 | HIGH 8.1 | cisco firepower_management_center_virtual_appliance A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device crede | 2.0% | — |
| CVE-2021-34739 | HIGH 8.1 | cisco cbs250-16p-2g_firmware A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized access to the web-based management interface o | 1.7% | — |
| CVE-2021-34718 | HIGH 8.1 | cisco ios_xr A vulnerability in the SSH Server process of Cisco IOS XR Software could allow an authenticated, remote attacker to overwrite and read arbitrary files on the local device. This vulnerability is due to insufficient input validation of arguments that are supplie | 1.6% | — |
| CVE-2021-34551 | HIGH 8.1 | fedoraproject fedora PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname. | 2.8% | — |
| CVE-2021-34524 | HIGH 8.1 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 3.6% | — |
| CVE-2021-34520 | HIGH 8.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 4.4% | — |
| CVE-2021-34492 | HIGH 8.1 | microsoft windows_10 Windows Certificate Spoofing Vulnerability | 2.4% | — |
| CVE-2021-33786 | HIGH 8.1 | microsoft windows_server_2008 Windows LSA Security Feature Bypass Vulnerability | 2.1% | — |
| CVE-2021-33781 | HIGH 8.1 | microsoft windows_10 Azure AD Security Feature Bypass Vulnerability | 2.4% | — |
| CVE-2021-33779 | HIGH 8.1 | microsoft windows_server_2016 Windows AD FS Security Feature Bypass Vulnerability | 2.4% | — |
| CVE-2021-33113 | HIGH 8.1 | intel ac_1550_firmware Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access. | 0.7% | — |
| CVE-2021-32589 | HIGH 8.1 | fortinet fortianalyzer A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.2.10 and below, version 5.0.12 and below and FortiA | 8.7% | — |
| CVE-2021-31980 | HIGH 8.1 | microsoft intune_management_extension Microsoft Intune Management Extension Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-3062 | HIGH 8.1 | paloaltonetworks pan-os An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS. Exploitation of this | 0.7% | — |