57.065 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.065 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-25195 | HIGH 7.8 | microsoft windows_10 Windows PKU2U Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-24110 | HIGH 7.8 | microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-24108 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-24103 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-24102 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-24096 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2021-24092 | HIGH 7.8 | microsoft endpoint_protection Microsoft Defender Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-24091 | HIGH 7.8 | microsoft windows_10 Windows Camera Codec Pack Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2021-24090 | HIGH 7.8 | microsoft windows_10 Windows Error Reporting Elevation of Privilege Vulnerability | 3.5% | — |
| CVE-2021-24089 | HIGH 7.8 | microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability | 4.3% | — |
| CVE-2021-24083 | HIGH 7.8 | microsoft windows_10 Windows Address Book Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2021-24081 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Codecs Library Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-24070 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-24069 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-24068 | HIGH 7.8 | microsoft excel Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-24067 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-24023 | HIGH 7.8 | fortinet fortiai_firmware An improper input validation in FortiAI v1.4.0 and earlier may allow an authenticated user to gain system shell access via a malicious payload in the "diagnose" command. | 0.8% | — |
| CVE-2021-23134 | HIGH 7.8 | debian debian_linux Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability. | 0.4% | — |
| CVE-2021-23023 | HIGH 7.8 | f5 big-ip_access_policy_manager On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Client Windows Installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evalu | 0.3% | — |
| CVE-2021-23022 | HIGH 7.8 | f5 big-ip_access_policy_manager On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak file and folder permissions. Note: Software versions which have reached End of Technical Support (EoTS) are not ev | 0.2% | — |
| CVE-2021-23019 | HIGH 7.8 | f5 nginx_controller The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package. | 0.2% | — |
| CVE-2021-22980 | HIGH 7.8 | f5 access_policy_manager_clients In Edge Client version 7.2.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, and 7.1.x-7.1.8.x before 7.1.8.5, an untrusted search path vulnerability in the BIG-IP APM Client Troubleshooting Utility (CTU) for Windows could allow an attacker to load a malicious DLL lib | 0.3% | — |
| CVE-2021-22928 | HIGH 7.8 | citrix virtual_apps_and_desktops A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on tha | 0.2% | — |
| CVE-2021-22921 | HIGH 7.8 | nodejs node.js Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform | 7.4% | — |
| CVE-2021-22907 | HIGH 7.8 | citrix workspace An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4. | 0.2% | — |