57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-4203 | MED 6.8 | linux linux_kernel A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal ker | 1.7% | — |
| CVE-2021-41342 | MED 6.8 | microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2021-40114 | MED 6.8 | cisco secure_firewall_management_center Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is d | 2.4% | — |
| CVE-2021-39234 | MED 6.8 | apache ozone In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL. | 1.4% | — |
| CVE-2021-38204 | MED 6.8 | debian debian_linux drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations. | 0.3% | — |
| CVE-2021-36189 | MED 6.8 | fortinet forticlient_enterprise_management_server A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information disclosure via inspecting browser decrypted data | 0.4% | — |
| CVE-2021-35248 | MED 6.8 | solarwinds orion_platform It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings. | 0.9% | — |
| CVE-2021-35244 | MED 6.8 | solarwinds orion_platform The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file uploa | 5.8% | — |
| CVE-2021-34703 | MED 6.8 | cisco ios A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and Cisco IOS XE Software could allow an attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability i | 1.2% | — |
| CVE-2021-34534 | MED 6.8 | microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-34497 | MED 6.8 | microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2021-34480 | MED 6.8 | microsoft windows_10 Scripting Engine Memory Corruption Vulnerability | 33.9% | — |
| CVE-2021-34448 | MED 6.8 | microsoft windows_10_1507 Scripting Engine Memory Corruption Vulnerability | 40.1% | |
| CVE-2021-34447 | MED 6.8 | microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-33656 | MED 6.8 | debian debian_linux When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds. | 0.6% | — |
| CVE-2021-33478 | MED 6.8 | cisco ip_phone_8800_firmware The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitrary code execution in the TrustZone Trusted Execution Environment (TEE) of an affected device. This, for examp | 0.3% | — |
| CVE-2021-31971 | MED 6.8 | microsoft windows_10 Windows HTML Platforms Security Feature Bypass Vulnerability | 2.1% | — |
| CVE-2021-31378 | MED 6.8 | juniper junos In broadband environments, including but not limited to Enhanced Subscriber Management, (CHAP, PPP, DHCP, etc.), on Juniper Networks Junos OS devices where RADIUS servers are configured for managing subscriber access and a subscriber is logged in and then requ | 1.0% | — |
| CVE-2021-3046 | MED 6.8 | paloaltonetworks pan-os An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentica | 1.1% | — |
| CVE-2021-27092 | MED 6.8 | microsoft windows_10 Azure AD Web Sign-in Security Feature Bypass Vulnerability | 2.6% | — |
| CVE-2021-27075 | MED 6.8 | microsoft azure_container_instances Azure Virtual Machine Information Disclosure Vulnerability | 1.4% | — |
| CVE-2021-26105 | MED 6.8 | fortinet fortisandbox A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted HTTP | 0.5% | — |
| CVE-2021-25220 | MED 6.8 | fedoraproject fedora BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to | 3.4% | — |
| CVE-2021-24109 | MED 6.8 | microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2021-24075 | MED 6.8 | microsoft windows_10 Microsoft Windows VMSwitch Denial of Service Vulnerability | 2.4% | — |