IT
58.327 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.327 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-3772 MED 6.5 debian debian_linux A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses. 1.2% —
CVE-2021-37533 MED 6.5 apache commons_net Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may le 2.1% —
CVE-2021-36774 MED 6.5 apache kylin Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server within 1.9% —
CVE-2021-36749 MED 6.5 apache druid In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of th 80.9% —
CVE-2021-36168 MED 6.5 fortinet fortiportal A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET r 1.1% —
CVE-2021-35240 MED 6.5 solarwinds orion_platform A security researcher stored XSS via a Help Server setting. This affects customers using Internet Explorer, because they do not support 'rel=noopener'. 1.1% —
CVE-2021-34786 MED 6.5 cisco broadworks_commpilot_application_software Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system. 1.0% —
CVE-2021-34785 MED 6.5 cisco broadworks_commpilot_application_software Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system. 1.3% —
CVE-2021-34773 MED 6.5 cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Un 0.5% —
CVE-2021-34734 MED 6.5 cisco video_surveillance_7000_ip_camera_firmware A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for the Cisco Video Surveillance 7000 Series IP Cameras firmware could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is du 0.4% —
CVE-2021-34707 MED 6.5 cisco evolved_programmable_network_manager A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently protect s 1.1% —
CVE-2021-34507 MED 6.5 microsoft windows_10 Windows Remote Assistance Information Disclosure Vulnerability 3.2% —
CVE-2021-34499 MED 6.5 microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability 2.8% —
CVE-2021-34444 MED 6.5 microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability 3.5% —
CVE-2021-33783 MED 6.5 microsoft windows_10 Windows SMB Information Disclosure Vulnerability 2.8% —
CVE-2021-33745 MED 6.5 microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability 2.8% —
CVE-2021-33110 MED 6.5 intel ac_1550_firmware Improper input validation for some Intel(R) Wireless Bluetooth(R) products and Killer(TM) Bluetooth(R) products in Windows 10 and 11 before version 22.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access. 0.5% —
CVE-2021-32595 MED 6.5 fortinet fortiportal Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a single low-privileged user to induce a denial of service via multiple HTTP requests. 0.8% —
CVE-2021-32593 MED 6.5 fortinet fortiwan A use of a broken or risky cryptographic algorithm vulnerability [CWE-327] in the Dynamic Tunnel Protocol of FortiWAN before 4.5.9 may allow an unauthenticated remote attacker to decrypt and forge protocol communication messages. 0.6% —
CVE-2021-3178 MED 6.5 debian debian_linux fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export 2.4% —
CVE-2021-31382 MED 6.5 juniper junos On PTX1000 System, PTX10002-60C System, after upgrading to an affected release, a Race Condition vulnerability between the chassis daemon (chassisd) and firewall process (dfwd) of Juniper Networks Junos OS, may update the device's interfaces with incorrect fir 0.6% —
CVE-2021-31381 MED 6.5 juniper session_and_resource_control A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a specially crafted query to cause the web server to delete files which may allow the attacker to disrupt the integrity 1.2% —
CVE-2021-31370 MED 6.5 juniper junos An Incomplete List of Disallowed Inputs vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX5000 Series and EX4600 Series allows an adjacent unauthenticated attacker which sends a high rate of specific multicast traffic to cause 0.4% —
CVE-2021-31367 MED 6.5 juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows an adjacent attacker to cause a Denial of Service (DoS) by sending genuine BGP flowspec packets which cau 0.4% —
CVE-2021-31366 MED 6.5 juniper junos An Unchecked Return Value vulnerability in the authd (authentication daemon) of Juniper Networks Junos OS on MX Series configured for subscriber management / BBE allows an adjacent attacker to cause a crash by sending a specific username. This impacts authenti 0.4% —