57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.620 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-29777 | MED 6.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropped while being accessed in another session, could allow an authenticated user to cause a denial of srevice IBM | 1.4% | — |
| CVE-2021-29770 | MED 6.5 | ibm i2_analyze IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 202771. | 0.6% | — |
| CVE-2021-29683 | MED 6.5 | ibm security_identity_manager IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998. | 0.5% | — |
| CVE-2021-28715 | MED 6.5 | debian debian_linux Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's | 0.3% | — |
| CVE-2021-28714 | MED 6.5 | debian debian_linux Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's | 0.3% | — |
| CVE-2021-28688 | MED 6.5 | debian debian_linux The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went too far and may under certain conditions also overwrite pointers which are in need of cleaning up. Th | 0.3% | — |
| CVE-2021-28655 | MED 6.5 | apache zeppelin The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions. | 1.5% | — |
| CVE-2021-28555 | MED 6.5 | adobe acrobat Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to get access to | 2.8% | — |
| CVE-2021-28546 | MED 6.5 | adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker could leverage this vulnerability to modify content in a cer | 1.4% | — |
| CVE-2021-28442 | MED 6.5 | microsoft windows_10 Windows TCP/IP Information Disclosure Vulnerability | 6.5% | — |
| CVE-2021-28441 | MED 6.5 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28328 | MED 6.5 | microsoft windows_10 Windows DNS Information Disclosure Vulnerability | 2.5% | — |
| CVE-2021-28325 | MED 6.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 62.1% | — |
| CVE-2021-28323 | MED 6.5 | microsoft windows_10 Windows DNS Information Disclosure Vulnerability | 4.3% | — |
| CVE-2021-28311 | MED 6.5 | microsoft windows_10 Windows Application Compatibility Cache Denial of Service Vulnerability | 2.5% | — |
| CVE-2021-28039 | MED 6.5 | linux linux_kernel An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical | 0.4% | — |
| CVE-2021-28038 | MED 6.5 | debian debian_linux An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host | 0.7% | — |
| CVE-2021-27067 | MED 6.5 | microsoft azure_devops_server Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability | 2.6% | — |
| CVE-2021-26920 | MED 6.5 | apache druid In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of th | 9.9% | — |
| CVE-2021-26559 | MED 6.5 | apache airflow Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg` | 2.8% | — |
| CVE-2021-26421 | MED 6.5 | microsoft lync_server Skype for Business and Lync Spoofing Vulnerability | 1.4% | — |
| CVE-2021-26111 | MED 6.5 | fortinet fortiswitch A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below may allow an attacker on an adjacent network to exhaust available memory by sending specifically crafted LLDP/CDP | 0.4% | — |
| CVE-2021-25958 | MED 6.5 | apache ofbiz In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he | 2.6% | — |
| CVE-2021-24101 | MED 6.5 | microsoft dynamics_365 Microsoft Dataverse Information Disclosure Vulnerability | 2.8% | — |
| CVE-2021-24099 | MED 6.5 | microsoft lync_server Skype for Business and Lync Denial of Service Vulnerability | 2.9% | — |