57.065 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.065 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-28457 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-28454 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2021-28453 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 4.1% | — |
| CVE-2021-28451 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28449 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-28448 | HIGH 7.8 | microsoft visual_studio_code_kubernetes_tools Visual Studio Code Kubernetes Tools Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28436 | HIGH 7.8 | microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-28375 | HIGH 7.8 | fedoraproject fedora An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308. | 0.3% | — |
| CVE-2021-28351 | HIGH 7.8 | microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-28350 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2021-28349 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2021-28348 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2021-28347 | HIGH 7.8 | microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-28322 | HIGH 7.8 | microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-28321 | HIGH 7.8 | microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2021-28320 | HIGH 7.8 | microsoft windows_10 Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-28315 | HIGH 7.8 | microsoft windows_10 Windows Media Video Decoder Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2021-28314 | HIGH 7.8 | microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-28313 | HIGH 7.8 | microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-28310 | HIGH 7.8 | microsoft windows_10_1803 Win32k Elevation of Privilege Vulnerability | 8.3% | |
| CVE-2021-28130 | HIGH 7.8 | drweb security_space Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload within a legitimate binary (e.g., frwl_svc.exe) bypasses firewall filters. | 0.4% | — |
| CVE-2021-28129 | HIGH 7.8 | apache openoffice While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by t | 0.5% | — |
| CVE-2021-27892 | HIGH 7.8 | ssh tectia_client SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation. ConnectSecure on Windows is affected. | 0.3% | — |
| CVE-2021-27365 | HIGH 7.8 | debian debian_linux An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, a | 2.1% | — |
| CVE-2021-27271 | HIGH 7.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 3.3% | — |