57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22998 | HIGH 8.0 | westerndigital my_cloud_home_duo_firmware Implemented protections on AWS credentials that were not properly protected. | 0.8% | — |
| CVE-2022-22181 | HIGH 8.0 | juniper junos A reflected Cross-site Scripting (XSS) vulnerability in J-Web of Juniper Networks Junos OS allows a network-based authenticated attacker to run malicious scripts reflected off J-Web to the victim's browser in the context of their session within J-Web. This may | 0.7% | — |
| CVE-2022-21987 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 2.0% | — |
| CVE-2022-21980 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 2.5% | — |
| CVE-2022-21893 | HIGH 8.0 | microsoft windows_10 Remote Desktop Protocol Remote Code Execution Vulnerability | 7.9% | — |
| CVE-2021-42320 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.5% | — |
| CVE-2021-4157 | HIGH 8.0 | fedoraproject fedora An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system | 1.6% | — |
| CVE-2021-41348 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-40464 | HIGH 8.0 | microsoft windows_10 Windows Nearby Sharing Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-40461 | HIGH 8.0 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2021-38963 | HIGH 8.0 | ibm aspera_console IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnera | 0.6% | — |
| CVE-2021-38672 | HIGH 8.0 | microsoft windows_11 Windows Hyper-V Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-36967 | HIGH 8.0 | microsoft windows_10 Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-36179 | HIGH 8.0 | fortinet fortiweb A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows attacker to execute unauthorized code or commands via crafted parameters in CLI command execution | 1.6% | — |
| CVE-2021-36173 | HIGH 8.0 | fortinet fortios A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 may allow an attacker to execute arbitrary code via specially crafted installation | 1.4% | — |
| CVE-2021-35222 | HIGH 8.0 | solarwinds orion_platform This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Settings page. | 2.6% | — |
| CVE-2021-34474 | HIGH 8.0 | microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-34470 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 4.4% | — |
| CVE-2021-34446 | HIGH 8.0 | microsoft windows_10 Windows HTML Platforms Security Feature Bypass Vulnerability | 2.0% | — |
| CVE-2021-33768 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2021-33754 | HIGH 8.0 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-33746 | HIGH 8.0 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-31373 | HIGH 8.0 | juniper junos A persistent Cross-Site Scripting (XSS) vulnerability in Juniper Networks Junos OS on SRX Series, J-Web interface may allow a remote authenticated user to inject persistent and malicious scripts. An attacker can exploit this vulnerability to steal sensitive da | 0.8% | — |
| CVE-2021-31355 | HIGH 8.0 | juniper junos A persistent cross-site scripting (XSS) vulnerability in the captive portal graphical user interface of Juniper Networks Junos OS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administrat | 0.8% | — |
| CVE-2021-3052 | HIGH 8.0 | paloaltonetworks pan-os A reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface enables an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performs arbitrar | 0.6% | — |