58.306 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-33782 | MED 5.5 | microsoft windows_10 Windows Authenticode Spoofing Vulnerability | 2.2% | — |
| CVE-2021-33763 | MED 5.5 | microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-33760 | MED 5.5 | microsoft windows_10 Media Foundation Information Disclosure Vulnerability | 1.0% | — |
| CVE-2021-33603 | MED 5.5 | f-secure atlant A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack w | 0.6% | — |
| CVE-2021-31978 | MED 5.5 | microsoft malware_protection_engine Microsoft Defender Denial of Service Vulnerability | 1.2% | — |
| CVE-2021-31972 | MED 5.5 | microsoft windows_10 Event Tracing for Windows Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-31970 | MED 5.5 | microsoft windows_10 Windows TCP/IP Driver Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2021-31960 | MED 5.5 | microsoft windows_10 Windows Bind Filter Driver Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-31955 | MED 5.5 | microsoft windows_10_1809 Windows Kernel Information Disclosure Vulnerability | 81.1% | |
| CVE-2021-31829 | MED 5.5 | debian debian_linux kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculativ | 0.3% | — |
| CVE-2021-31821 | MED 5.5 | octopus tentacle When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API key in plaintext. This does not affect the Linux Docker image | 0.2% | — |
| CVE-2021-31812 | MED 5.5 | apache pdfbox In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. | 3.1% | — |
| CVE-2021-31811 | MED 5.5 | apache pdfbox In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. | 3.4% | — |
| CVE-2021-31471 | MED 5.5 | foxitsoftware 3d This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious f | 2.1% | — |
| CVE-2021-31377 | MED 5.5 | juniper junos An Incorrect Permission Assignment for Critical Resource vulnerability of a certain file in the filesystem of Junos OS allows a local authenticated attacker to cause routing process daemon (RPD) to crash and restart, causing a Denial of Service (DoS). Repeated | 0.2% | — |
| CVE-2021-31191 | MED 5.5 | microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-31185 | MED 5.5 | microsoft windows_10 Windows Desktop Bridge Denial of Service Vulnerability | 0.6% | — |
| CVE-2021-31184 | MED 5.5 | microsoft windows_10 Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability | 1.6% | — |
| CVE-2021-31178 | MED 5.5 | microsoft 365_apps Microsoft Office Information Disclosure Vulnerability | 16.0% | — |
| CVE-2021-31174 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 2.9% | — |
| CVE-2021-3038 | MED 5.5 | paloaltonetworks globalprotect A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems allows a limited Windows user to send specifically-crafted input to the GlobalProtect app that results in a Windows blue screen of death (BSOD) error. This issue | 0.2% | — |
| CVE-2021-30178 | MED 5.5 | fedoraproject fedora An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer dereference for certain accesses to the SynIC Hyper-V context, aka CID-919f4ebc5987. | 0.3% | — |
| CVE-2021-29904 | MED 5.5 | ibm jazz_for_service_management IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610. | 0.2% | — |
| CVE-2021-29650 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a full memory barrier upon the assignment of | 0.4% | — |
| CVE-2021-29649 | MED 5.5 | fedoraproject fedora An issue was discovered in the Linux kernel before 5.11.11. The user mode driver (UMD) has a copy_process() memory leak, related to a lack of cleanup steps in kernel/usermode_driver.c and kernel/bpf/preload/bpf_preload_kern.c, aka CID-f60a85cad677. | 0.3% | — |