IT
58.306 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-28317 MED 5.5 microsoft windows_10 Microsoft Windows Codecs Library Information Disclosure Vulnerability 0.8% —
CVE-2021-28309 MED 5.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 0.8% —
CVE-2021-27906 MED 5.5 apache pdfbox A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. 3.3% —
CVE-2021-27807 MED 5.5 apache pdfbox A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. 3.0% —
CVE-2021-27093 MED 5.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 0.8% —
CVE-2021-26932 MED 5.5 debian debian_linux An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in batch hypercalls, where a number of operations are done in a single hypercall, the success or failure of each one is reported to the backen 0.3% —
CVE-2021-26931 MED 5.5 debian debian_linux An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at least under the influence of guests (suc 0.6% —
CVE-2021-26884 MED 5.5 microsoft windows_10 Windows Media Photo Codec Information Disclosure Vulnerability 1.0% —
CVE-2021-26869 MED 5.5 microsoft windows_10 Windows ActiveX Installer Service Information Disclosure Vulnerability 1.0% —
CVE-2021-26437 MED 5.5 microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability 2.3% —
CVE-2021-26417 MED 5.5 microsoft windows_10 Windows Overlay Filter Information Disclosure Vulnerability 0.8% —
CVE-2021-25252 MED 5.5 trendmicro apex_central Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file. 0.6% —
CVE-2021-25248 MED 5.5 trendmicro apex_one An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Ple 0.9% —
CVE-2021-24107 MED 5.5 microsoft windows_10 Windows Event Tracing Information Disclosure Vulnerability 1.0% —
CVE-2021-24106 MED 5.5 microsoft windows_10 Windows DirectX Information Disclosure Vulnerability 0.9% —
CVE-2021-24098 MED 5.5 microsoft windows_10 Windows Console Driver Denial of Service Vulnerability 1.5% —
CVE-2021-24084 MED 5.5 microsoft windows_10 Windows Mobile Device Management Information Disclosure Vulnerability 2.8% —
CVE-2021-24079 MED 5.5 microsoft windows_10 Windows Backup Engine Information Disclosure Vulnerability 0.9% —
CVE-2021-24076 MED 5.5 microsoft windows_10 Microsoft Windows VMSwitch Information Disclosure Vulnerability 0.9% —
CVE-2021-23827 MED 5.5 keybase keybase Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, ev 0.3% —
CVE-2021-23021 MED 5.5 f5 nginx_controller The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to 644. 0.2% —
CVE-2021-23020 MED 5.5 f5 nginx_controller The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys. 0.3% —
CVE-2021-22020 MED 5.5 vmware cloud_foundation The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server. 0.2% —
CVE-2021-22007 MED 5.5 vmware cloud_foundation The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue to gain access to sensitive information. 0.2% —
CVE-2021-21997 MED 5.5 vmware tools VMware Tools for Windows (11.x.y prior to 11.3.0) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest operating system, where VMware Tools is installed, can trigger a PANIC in the V 0.7% —