58.327 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.327 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-41571 | MED 6.5 | apache pulsar In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API get-message-by-id requires the user to input a topic and a ledger id. The ledger id is a pointer to the data, | 1.7% | — |
| CVE-2021-41350 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 1.9% | — |
| CVE-2021-41349 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 93.5% | — |
| CVE-2021-41332 | MED 6.5 | microsoft windows_10 Windows Print Spooler Information Disclosure Vulnerability | 2.7% | — |
| CVE-2021-41026 | MED 6.5 | fortinet fortiweb A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests. | 0.9% | — |
| CVE-2021-40460 | MED 6.5 | microsoft windows_10 Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability | 1.6% | — |
| CVE-2021-40439 | MED 6.5 | apache openoffice Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consist of a set of XML files. All versions of | 3.9% | — |
| CVE-2021-40120 | MED 6.5 | cisco application_extension_platform A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system and execute t | 2.0% | — |
| CVE-2021-40111 | MED 6.5 | apache james In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP command could be used to trigger infinite loops resulting in expensive CPU computations and OutOfMemory exceptions. This can be used for a Denial | 2.1% | — |
| CVE-2021-39856 | MED 6.5 | adobe acrobat Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obt | 2.4% | — |
| CVE-2021-39855 | MED 6.5 | adobe acrobat Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obt | 2.4% | — |
| CVE-2021-39532 | MED 6.5 | juniper libslax An issue was discovered in libslax through v0.22.1. A NULL pointer dereference exists in the function slaxLexer() located in slaxlexer.c. It allows an attacker to cause Denial of Service. | 0.9% | — |
| CVE-2021-39235 | MED 6.5 | apache ozone In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block. | 1.6% | — |
| CVE-2021-39087 | MED 6.5 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission controls. IBM X-Force ID: 216109. | 0.6% | — |
| CVE-2021-39033 | MED 6.5 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in | 1.0% | — |
| CVE-2021-39019 | MED 6.5 | ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information through an HTTP GET request to an authenticated user. IBM X-Force ID: 213728. | 0.8% | — |
| CVE-2021-39017 | MED 6.5 | ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 213725. | 0.9% | — |
| CVE-2021-38975 | MED 6.5 | ibm security_guardium_key_lifecycle_manager IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 212780. | 1.0% | — |
| CVE-2021-38974 | MED 6.5 | ibm security_guardium_key_lifecycle_manager IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to cause a denial of service using specially crafted HTTP requests. IBM X-Force ID: 212779. | 1.0% | — |
| CVE-2021-38931 | MED 6.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from. IBM X-Force ID: 210 | 1.2% | — |
| CVE-2021-38629 | MED 6.5 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability | 2.7% | — |
| CVE-2021-38624 | MED 6.5 | microsoft windows_10 Windows Key Storage Provider Security Feature Bypass Vulnerability | 1.5% | — |
| CVE-2021-38505 | MED 6.5 | mozilla firefox Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data fro | 1.1% | — |
| CVE-2021-38492 | MED 6.5 | mozilla firefox When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating sys | 1.2% | — |
| CVE-2021-38199 | MED 6.5 | debian debian_linux fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking dete | 1.2% | — |