56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.793 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-44548 | CRIT 9.8 | apache solr An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB network call being made from the Solr host to another host on the network. If the attacker has wider access to t | 5.1% | — |
| CVE-2021-43907 | CRIT 9.8 | microsoft windows_subsystem_for_linux Visual Studio Code WSL Extension Remote Code Execution Vulnerability | 3.8% | — |
| CVE-2021-43899 | CRIT 9.8 | microsoft wireless_display_adapter_firmware Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-43350 | CRIT 9.8 | apache traffic_control An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter. | 4.4% | — |
| CVE-2021-43297 | CRIT 9.8 | apache dubbo A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessian catch unexpected ex | 17.0% | — |
| CVE-2021-43267 | CRIT 9.8 | fedoraproject fedora An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type. | 57.6% | — |
| CVE-2021-43215 | CRIT 9.8 | microsoft windows_10 iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution | 2.7% | — |
| CVE-2021-43082 | CRIT 9.8 | apache traffic_server Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0. | 2.4% | — |
| CVE-2021-42756 | CRIT 9.8 | fortinet fortiweb Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbit | 35.0% | — |
| CVE-2021-42013 | CRIT 9.8 | ransomware apache http_server It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories ar | 100.0% | |
| CVE-2021-42010 | CRIT 9.8 | apache heron Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue. | 1.6% | — |
| CVE-2021-41773 | CRIT 9.8 | ransomware apache http_server A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not | 100.0% | |
| CVE-2021-41616 | CRIT 9.8 | apache ddlutils Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINARY, LONGVARBINARY, or BLOB between databases using the ddlutils features. The BinaryObjectsHelper class was inse | 3.5% | — |
| CVE-2021-41303 | CRIT 9.8 | apache shiro Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0. | 76.7% | — |
| CVE-2021-40865 | CRIT 9.8 | apache storm An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrad | 65.6% | — |
| CVE-2021-40146 | CRIT 9.8 | apache any23 A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machine over LAN, WAN, or i | 5.7% | — |
| CVE-2021-40119 | CRIT 9.8 | cisco policy_suite A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user. This vulnerability is due to the re-use of static SSH keys across installation | 2.5% | — |
| CVE-2021-39275 | CRIT 9.8 | apache http_server ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier. | 39.4% | — |
| CVE-2021-39085 | CRIT 9.8 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, ad | 0.9% | — |
| CVE-2021-39065 | CRIT 9.8 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the Spectrum Copy Data Management Admin Console login and uploadcertificate | 2.2% | — |
| CVE-2021-39052 | CRIT 9.8 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-Force ID: 214523. | 1.1% | — |
| CVE-2021-38869 | CRIT 9.8 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341. | 0.9% | — |
| CVE-2021-38647 | CRIT 9.8 | ransomware microsoft azure_automation_state_configuration Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | 99.9% | |
| CVE-2021-38540 | CRIT 9.8 | apache airflow The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclos | 80.9% | — |
| CVE-2021-38294 | CRIT 9.8 | apache storm A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentic | 84.5% | — |