56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-3060 | HIGH 8.1 | paloaltonetworks pan-os An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root use | 33.9% | — |
| CVE-2021-3059 | HIGH 8.1 | paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerability enables a man-in-the-middle attacker to execute arbitrary OS commands to escalate privileges. This issue impa | 1.5% | — |
| CVE-2021-3057 | HIGH 8.1 | paloaltonetworks globalprotect A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This issue impacts: GlobalProtec | 1.4% | — |
| CVE-2021-3051 | HIGH 8.1 | paloaltonetworks cortex_xsoar An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform u | 0.6% | — |
| CVE-2021-29986 | HIGH 8.1 | mozilla firefox A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, | 1.3% | — |
| CVE-2021-29968 | HIGH 8.1 | mozilla firefox When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.0.1. | 0.8% | — |
| CVE-2021-29644 | HIGH 8.1 | hitachi it_operations_director Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the under | 2.5% | — |
| CVE-2021-28545 | HIGH 8.1 | adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker would have the ability to completely manipulate data in a ce | 2.3% | — |
| CVE-2021-28460 | HIGH 8.1 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 0.5% | — |
| CVE-2021-28445 | HIGH 8.1 | microsoft windows_10 Windows Network File System Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-26701 | HIGH 8.1 | fedoraproject fedora .NET Core Remote Code Execution Vulnerability | 30.1% | — |
| CVE-2021-26639 | HIGH 8.1 | wisa smart_wing_cms This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system. | 0.5% | — |
| CVE-2021-26626 | HIGH 8.1 | tobesoft xplatform Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the second parameter value of the execBrowser function is ‘default’, the first parameter value could be passed to the ShellExecuteW API. The pass | 1.2% | — |
| CVE-2021-26617 | HIGH 8.1 | firstmall firstmall This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows remote attackers to execute malicious code in Firstmall via navercheckout_add function. | 1.3% | — |
| CVE-2021-26613 | HIGH 8.1 | tobesoft nexacro improper input validation vulnerability in nexacro permits copying file to the startup folder using rename method. | 0.8% | — |
| CVE-2021-26612 | HIGH 8.1 | tobesoft nexacro An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code. | 1.2% | — |
| CVE-2021-26607 | HIGH 8.1 | tobesoft nexacro An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems. | 1.9% | — |
| CVE-2021-26435 | HIGH 8.1 | microsoft windows_10 Windows Scripting Engine Memory Corruption Vulnerability | 5.3% | — |
| CVE-2021-26112 | HIGH 8.1 | fortinet fortiwan Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpreter of FortiWAN before 4.5.9 may allow an unauthenticated attacker to potentially corrupt control data in memory and execute arbitrary code v | 1.7% | — |
| CVE-2021-26109 | HIGH 8.1 | fortinet fortios An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary | 1.8% | — |
| CVE-2021-24112 | HIGH 8.1 | microsoft .net .NET Core Remote Code Execution Vulnerability | 3.3% | — |
| CVE-2021-24019 | HIGH 8.1 | fortinet forticlient_endpoint_management_server An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that ses | 3.9% | — |
| CVE-2021-24010 | HIGH 8.1 | fortinet fortisandbox Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests. | 0.9% | — |
| CVE-2021-22927 | HIGH 8.1 | citrix application_delivery_controller_firmware A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session. | 0.8% | — |
| CVE-2021-21172 | HIGH 8.1 | debian debian_linux Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | 1.7% | — |