IT
57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.620 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-29777 MED 6.5 ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropped while being accessed in another session, could allow an authenticated user to cause a denial of srevice IBM 1.4%
CVE-2021-29770 MED 6.5 ibm i2_analyze IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 202771. 0.6%
CVE-2021-29683 MED 6.5 ibm security_identity_manager IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998. 0.5%
CVE-2021-28715 MED 6.5 debian debian_linux Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's 0.3%
CVE-2021-28714 MED 6.5 debian debian_linux Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's 0.3%
CVE-2021-28688 MED 6.5 debian debian_linux The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went too far and may under certain conditions also overwrite pointers which are in need of cleaning up. Th 0.3%
CVE-2021-28655 MED 6.5 apache zeppelin The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions. 1.5%
CVE-2021-28555 MED 6.5 adobe acrobat Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to get access to 2.8%
CVE-2021-28546 MED 6.5 adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker could leverage this vulnerability to modify content in a cer 1.4%
CVE-2021-28442 MED 6.5 microsoft windows_10 Windows TCP/IP Information Disclosure Vulnerability 6.5%
CVE-2021-28441 MED 6.5 microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability 0.8%
CVE-2021-28328 MED 6.5 microsoft windows_10 Windows DNS Information Disclosure Vulnerability 2.5%
CVE-2021-28325 MED 6.5 microsoft windows_10 Windows SMB Information Disclosure Vulnerability 62.1%
CVE-2021-28323 MED 6.5 microsoft windows_10 Windows DNS Information Disclosure Vulnerability 4.3%
CVE-2021-28311 MED 6.5 microsoft windows_10 Windows Application Compatibility Cache Denial of Service Vulnerability 2.5%
CVE-2021-28039 MED 6.5 linux linux_kernel An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical 0.4%
CVE-2021-28038 MED 6.5 debian debian_linux An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host 0.7%
CVE-2021-27067 MED 6.5 microsoft azure_devops_server Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability 2.6%
CVE-2021-26920 MED 6.5 apache druid In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of th 9.9%
CVE-2021-26559 MED 6.5 apache airflow Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg` 2.8%
CVE-2021-26421 MED 6.5 microsoft lync_server Skype for Business and Lync Spoofing Vulnerability 1.4%
CVE-2021-26111 MED 6.5 fortinet fortiswitch A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below may allow an attacker on an adjacent network to exhaust available memory by sending specifically crafted LLDP/CDP 0.4%
CVE-2021-25958 MED 6.5 apache ofbiz In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he 2.6%
CVE-2021-24101 MED 6.5 microsoft dynamics_365 Microsoft Dataverse Information Disclosure Vulnerability 2.8%
CVE-2021-24099 MED 6.5 microsoft lync_server Skype for Business and Lync Denial of Service Vulnerability 2.9%