IT
56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.960 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-3060 HIGH 8.1 paloaltonetworks pan-os An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root use 33.9%
CVE-2021-3059 HIGH 8.1 paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerability enables a man-in-the-middle attacker to execute arbitrary OS commands to escalate privileges. This issue impa 1.5%
CVE-2021-3057 HIGH 8.1 paloaltonetworks globalprotect A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This issue impacts: GlobalProtec 1.4%
CVE-2021-3051 HIGH 8.1 paloaltonetworks cortex_xsoar An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform u 0.6%
CVE-2021-29986 HIGH 8.1 mozilla firefox A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, 1.3%
CVE-2021-29968 HIGH 8.1 mozilla firefox When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.0.1. 0.8%
CVE-2021-29644 HIGH 8.1 hitachi it_operations_director Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the under 2.5%
CVE-2021-28545 HIGH 8.1 adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker would have the ability to completely manipulate data in a ce 2.3%
CVE-2021-28460 HIGH 8.1 microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability 0.5%
CVE-2021-28445 HIGH 8.1 microsoft windows_10 Windows Network File System Remote Code Execution Vulnerability 2.7%
CVE-2021-26701 HIGH 8.1 fedoraproject fedora .NET Core Remote Code Execution Vulnerability 30.1%
CVE-2021-26639 HIGH 8.1 wisa smart_wing_cms This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system. 0.5%
CVE-2021-26626 HIGH 8.1 tobesoft xplatform Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the second parameter value of the execBrowser function is ‘default’, the first parameter value could be passed to the ShellExecuteW API. The pass 1.2%
CVE-2021-26617 HIGH 8.1 firstmall firstmall This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows remote attackers to execute malicious code in Firstmall via navercheckout_add function. 1.3%
CVE-2021-26613 HIGH 8.1 tobesoft nexacro improper input validation vulnerability in nexacro permits copying file to the startup folder using rename method. 0.8%
CVE-2021-26612 HIGH 8.1 tobesoft nexacro An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code. 1.2%
CVE-2021-26607 HIGH 8.1 tobesoft nexacro An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems. 1.9%
CVE-2021-26435 HIGH 8.1 microsoft windows_10 Windows Scripting Engine Memory Corruption Vulnerability 5.3%
CVE-2021-26112 HIGH 8.1 fortinet fortiwan Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpreter of FortiWAN before 4.5.9 may allow an unauthenticated attacker to potentially corrupt control data in memory and execute arbitrary code v 1.7%
CVE-2021-26109 HIGH 8.1 fortinet fortios An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary 1.8%
CVE-2021-24112 HIGH 8.1 microsoft .net .NET Core Remote Code Execution Vulnerability 3.3%
CVE-2021-24019 HIGH 8.1 fortinet forticlient_endpoint_management_server An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that ses 3.9%
CVE-2021-24010 HIGH 8.1 fortinet fortisandbox Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests. 0.9%
CVE-2021-22927 HIGH 8.1 citrix application_delivery_controller_firmware A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session. 0.8%
CVE-2021-21172 HIGH 8.1 debian debian_linux Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. 1.7%