IT
57.065 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.065 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-26872 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.7%
CVE-2021-26871 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 1.4%
CVE-2021-26870 HIGH 7.8 microsoft windows_10 Windows Projected File System Elevation of Privilege Vulnerability 0.7%
CVE-2021-26868 HIGH 7.8 microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability 3.1%
CVE-2021-26861 HIGH 7.8 microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability 2.7%
CVE-2021-26860 HIGH 7.8 microsoft windows_10 Windows App-V Overlay Filter Elevation of Privilege Vulnerability 0.7%
CVE-2021-26858 HIGH 7.8 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 93.7%
CVE-2021-26857 HIGH 7.8 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 95.8%
CVE-2021-26700 HIGH 7.8 microsoft npm Visual Studio Code npm-script Extension Remote Code Execution Vulnerability 6.0%
CVE-2021-26677 HIGH 7.8 arubanetworks clearpass_policy_manager A local authenticated escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in ClearPass OnGuard could allow local authenticated users on a Windows platform to 0.3%
CVE-2021-26630 HIGH 7.8 handysoft groupware Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files. This vulnerability can be exploited by using the file download or execution path as the parameter value of the vulnerable funct 0.8%
CVE-2021-26623 HIGH 7.8 bandisoft bandizip A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code using this function. 1.1%
CVE-2021-26615 HIGH 7.8 bandisoft ark_library ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW function because of an integer overflow. 0.6%
CVE-2021-26441 HIGH 7.8 microsoft windows_10 Storage Spaces Controller Elevation of Privilege Vulnerability 0.9%
CVE-2021-26434 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability 0.9%
CVE-2021-26431 HIGH 7.8 microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability 1.2%
CVE-2021-26425 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.9%
CVE-2021-26415 HIGH 7.8 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 3.6%
CVE-2021-26115 HIGH 7.8 fortinet fortiwan An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.An OS command in 0.8%
CVE-2021-26110 HIGH 7.8 fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2.0.1 and below, 1.2.9 and below may allow an authenticated low-privileged attacker to escalate their privileges 0.2%
CVE-2021-26106 HIGH 7.8 fortinet fortiap An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5 may allow an authenticated attacker to execute unauthorized commands by running the kdbg CLI command with specif 0.3%
CVE-2021-26104 HIGH 7.8 fortinet fortianalyzer Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, FortiAnalyzer 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x an 3.0%
CVE-2021-25261 HIGH 7.8 yandex yandex_browser Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process 0.5%
CVE-2021-25249 HIGH 7.8 trendmicro apex_one An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. P 0.4%
CVE-2021-25247 HIGH 7.8 trendmicro housecall_for_home_networks A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker to use a malicious DLL to escalate privileges and perform arbitrary code execution. An attacker must already have user privileges on the ma 0.7%