IT
57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-22998 HIGH 8.0 westerndigital my_cloud_home_duo_firmware Implemented protections on AWS credentials that were not properly protected. 0.8%
CVE-2022-22181 HIGH 8.0 juniper junos A reflected Cross-site Scripting (XSS) vulnerability in J-Web of Juniper Networks Junos OS allows a network-based authenticated attacker to run malicious scripts reflected off J-Web to the victim's browser in the context of their session within J-Web. This may 0.7%
CVE-2022-21987 HIGH 8.0 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 2.0%
CVE-2022-21980 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 2.5%
CVE-2022-21893 HIGH 8.0 microsoft windows_10 Remote Desktop Protocol Remote Code Execution Vulnerability 7.9%
CVE-2021-42320 HIGH 8.0 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 1.5%
CVE-2021-4157 HIGH 8.0 fedoraproject fedora An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system 1.6%
CVE-2021-41348 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 0.6%
CVE-2021-40464 HIGH 8.0 microsoft windows_10 Windows Nearby Sharing Elevation of Privilege Vulnerability 0.6%
CVE-2021-40461 HIGH 8.0 microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability 1.4%
CVE-2021-38963 HIGH 8.0 ibm aspera_console IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnera 0.6%
CVE-2021-38672 HIGH 8.0 microsoft windows_11 Windows Hyper-V Remote Code Execution Vulnerability 1.1%
CVE-2021-36967 HIGH 8.0 microsoft windows_10 Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability 0.9%
CVE-2021-36179 HIGH 8.0 fortinet fortiweb A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows attacker to execute unauthorized code or commands via crafted parameters in CLI command execution 1.6%
CVE-2021-36173 HIGH 8.0 fortinet fortios A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 may allow an attacker to execute arbitrary code via specially crafted installation 1.4%
CVE-2021-35222 HIGH 8.0 solarwinds orion_platform This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Settings page. 2.6%
CVE-2021-34474 HIGH 8.0 microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability 2.2%
CVE-2021-34470 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 4.4%
CVE-2021-34446 HIGH 8.0 microsoft windows_10 Windows HTML Platforms Security Feature Bypass Vulnerability 2.0%
CVE-2021-33768 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 1.2%
CVE-2021-33754 HIGH 8.0 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 2.0%
CVE-2021-33746 HIGH 8.0 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 2.0%
CVE-2021-31373 HIGH 8.0 juniper junos A persistent Cross-Site Scripting (XSS) vulnerability in Juniper Networks Junos OS on SRX Series, J-Web interface may allow a remote authenticated user to inject persistent and malicious scripts. An attacker can exploit this vulnerability to steal sensitive da 0.8%
CVE-2021-31355 HIGH 8.0 juniper junos A persistent cross-site scripting (XSS) vulnerability in the captive portal graphical user interface of Juniper Networks Junos OS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administrat 0.8%
CVE-2021-3052 HIGH 8.0 paloaltonetworks pan-os A reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface enables an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performs arbitrar 0.6%