IT
57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.620 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-42809 MED 6.5 thalesgroup sentinel_protection_installer Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code. 0.3%
CVE-2021-42808 MED 6.5 thalesgroup sentinel_protection_installer Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges. 0.2%
CVE-2021-42305 MED 6.5 microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability 7.9%
CVE-2021-42293 MED 6.5 microsoft 365_apps Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability 2.8%
CVE-2021-42250 MED 6.5 apache superset Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs. 1.8%
CVE-2021-41973 MED 6.5 apache mina In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update M 4.7%
CVE-2021-41972 MED 6.5 apache superset Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way. 1.5%
CVE-2021-41767 MED 6.5 apache guacamole Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact w 1.9%
CVE-2021-41571 MED 6.5 apache pulsar In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API get-message-by-id requires the user to input a topic and a ledger id. The ledger id is a pointer to the data, 1.7%
CVE-2021-41350 MED 6.5 microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability 1.9%
CVE-2021-41349 MED 6.5 microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability 93.5%
CVE-2021-41332 MED 6.5 microsoft windows_10 Windows Print Spooler Information Disclosure Vulnerability 2.7%
CVE-2021-41026 MED 6.5 fortinet fortiweb A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests. 0.9%
CVE-2021-40460 MED 6.5 microsoft windows_10 Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability 1.6%
CVE-2021-40439 MED 6.5 apache openoffice Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consist of a set of XML files. All versions of 3.9%
CVE-2021-40120 MED 6.5 cisco application_extension_platform A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system and execute t 2.0%
CVE-2021-40111 MED 6.5 apache james In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP command could be used to trigger infinite loops resulting in expensive CPU computations and OutOfMemory exceptions. This can be used for a Denial 2.1%
CVE-2021-39856 MED 6.5 adobe acrobat Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obt 2.4%
CVE-2021-39855 MED 6.5 adobe acrobat Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obt 2.4%
CVE-2021-39532 MED 6.5 juniper libslax An issue was discovered in libslax through v0.22.1. A NULL pointer dereference exists in the function slaxLexer() located in slaxlexer.c. It allows an attacker to cause Denial of Service. 0.9%
CVE-2021-39235 MED 6.5 apache ozone In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block. 1.6%
CVE-2021-39087 MED 6.5 ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission controls. IBM X-Force ID: 216109. 0.6%
CVE-2021-39033 MED 6.5 ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in 1.0%
CVE-2021-39019 MED 6.5 ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information through an HTTP GET request to an authenticated user. IBM X-Force ID: 213728. 0.8%
CVE-2021-39017 MED 6.5 ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 213725. 0.9%