58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-31360 | HIGH 7.1 | juniper junos An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) allows a low-privileged user to overwrite local files as root, possibly leading to a system integrity issue or Denial of Service | 0.2% | — |
| CVE-2021-31354 | HIGH 7.1 | juniper junos An Out Of Bounds (OOB) access vulnerability in the handling of responses by a Juniper Agile License (JAL) Client in Juniper Networks Junos OS and Junos OS Evolved, configured in Network Mode (to use Juniper Agile License Manager) may allow an attacker to cause | 0.6% | — |
| CVE-2021-31182 | HIGH 7.1 | microsoft windows_10 Microsoft Bluetooth Driver Spoofing Vulnerability | 0.8% | — |
| CVE-2021-31172 | HIGH 7.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1.8% | — |
| CVE-2021-29964 | HIGH 7.1 | mozilla firefox A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thun | 0.8% | — |
| CVE-2021-28452 | HIGH 7.1 | microsoft 365_apps Microsoft Outlook Memory Corruption Vulnerability | 1.3% | — |
| CVE-2021-28446 | HIGH 7.1 | microsoft windows_10 Windows Portmapping Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-27364 | HIGH 7.1 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages. | 1.0% | — |
| CVE-2021-26866 | HIGH 7.1 | microsoft windows_10 Windows Update Service Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-26619 | HIGH 7.1 | bigfile bigfileagent An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent. Remote attackers can use this vulnerability to delete arbitrary files of unspecified number of users. | 0.9% | — |
| CVE-2021-26618 | HIGH 7.1 | tmax tooffice An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers use this vulnerability to execute arbitrary file included malicious code. | 1.0% | — |
| CVE-2021-26420 | HIGH 7.1 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 3.0% | — |
| CVE-2021-26088 | HIGH 7.1 | fortinet fortinet_single_sign-on An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets. | 1.0% | — |
| CVE-2021-22128 | HIGH 7.1 | fortinet fortiproxy An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connection functi | 1.0% | — |
| CVE-2021-22127 | HIGH 7.1 | fortinet forticlient An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x before 6.2.9 may allow an unauthenticated attacker to execute arbitrary code on the host operating system as root via tricking the user into con | 0.5% | — |
| CVE-2021-21315 | HIGH 7.1 | apache cordova The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerabilit | 90.7% | |
| CVE-2021-21076 | HIGH 7.1 | adobe animate Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requir | 3.2% | — |
| CVE-2021-21075 | HIGH 7.1 | adobe animate Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requir | 3.0% | — |
| CVE-2021-21074 | HIGH 7.1 | adobe animate Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requir | 3.2% | — |
| CVE-2021-21072 | HIGH 7.1 | adobe animate Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requir | 3.0% | — |
| CVE-2021-1729 | HIGH 7.1 | microsoft windows_10 Windows Update Stack Setup Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-1365 | HIGH 7.1 | cisco unified_communications_manager_im_and_presence_service Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilities are due | 1.1% | — |
| CVE-2021-1363 | HIGH 7.1 | cisco unified_communications_manager_im_and_presence_service Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilities are due | 1.1% | — |
| CVE-2021-1086 | HIGH 7.1 | nvidia virtual_gpu_manager NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it allows guests to control unauthorized resources, which may lead to integrity and confidentiality loss or information disclosure. This affects vGPU version 12.x (prior | 0.2% | — |
| CVE-2021-1065 | HIGH 7.1 | nvidia virtual_gpu_manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3). | 0.3% | — |