57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.620 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-24085 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 4.6% | — |
| CVE-2021-24080 | MED 6.5 | microsoft windows_10 Windows Trust Verification API Denial of Service Vulnerability | 2.9% | — |
| CVE-2021-24073 | MED 6.5 | microsoft lync_server Skype for Business and Lync Spoofing Vulnerability | 1.6% | — |
| CVE-2021-24012 | MED 6.5 | fortinet fortios An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority. | 0.5% | — |
| CVE-2021-23055 | MED 6.5 | f5 nginx_ingress_controller On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evalua | 0.8% | — |
| CVE-2021-23043 | MED 6.5 | f5 big-ip_access_policy_manager On BIG-IP, on all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to access arbitrary files. Note: Software ve | 2.0% | — |
| CVE-2021-22920 | MED 6.5 | citrix application_delivery_management A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, co | 0.9% | — |
| CVE-2021-22097 | MED 6.5 | vmware spring_advanced_message_queuing_protocol In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util | 1.1% | — |
| CVE-2021-22095 | MED 6.5 | vmware spring_advanced_message_queuing_protocol In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message | 1.0% | — |
| CVE-2021-22051 | MED 6.5 | vmware spring_cloud_gateway Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users | 0.7% | — |
| CVE-2021-22036 | MED 6.5 | vmware vrealize_automation VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled domain due to improper path handling in vRealize Orchestrator lea | 0.9% | — |
| CVE-2021-22018 | MED 6.5 | vmware cloud_foundation The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files. | 1.1% | — |
| CVE-2021-21993 | MED 6.5 | vmware cloud_foundation The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library. An authorised user with access to content library may exploit this issue by sending a POST request to vCenter | 0.9% | — |
| CVE-2021-21992 | MED 6.5 | vmware cloud_foundation The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may exploit t | 1.0% | — |
| CVE-2021-21989 | MED 6.5 | vmware horizon_client VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be | 0.5% | — |
| CVE-2021-21988 | MED 6.5 | vmware horizon_client VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (JPEG2000 Parser). A malicious actor with access to a virtual machine or remote desktop ma | 0.5% | — |
| CVE-2021-21987 | MED 6.5 | vmware horizon_client VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be | 0.6% | — |
| CVE-2021-21983 | MED 6.5 | vmware cloud_foundation Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying p | 68.6% | — |
| CVE-2021-21683 | MED 6.5 | jenkins jenkins The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Overall/Read permission (Windows controller) or Job/Workspace p | 2.2% | — |
| CVE-2021-21178 | MED 6.5 | debian debian_linux Inappropriate implementation in Compositing in Google Chrome on Linux and Windows prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | 1.6% | — |
| CVE-2021-21141 | MED 6.5 | google chrome Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy via a crafted HTML page. | 5.4% | — |
| CVE-2021-21139 | MED 6.5 | google chrome Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | 4.7% | — |
| CVE-2021-21137 | MED 6.5 | google chrome Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page. | 5.9% | — |
| CVE-2021-21136 | MED 6.5 | google chrome Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | 4.2% | — |
| CVE-2021-21135 | MED 6.5 | google chrome Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | 19.2% | — |