58.335 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.335 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-28546 | MED 6.5 | adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker could leverage this vulnerability to modify content in a cer | 1.4% | — |
| CVE-2021-28442 | MED 6.5 | microsoft windows_10 Windows TCP/IP Information Disclosure Vulnerability | 6.5% | — |
| CVE-2021-28441 | MED 6.5 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28328 | MED 6.5 | microsoft windows_10 Windows DNS Information Disclosure Vulnerability | 2.5% | — |
| CVE-2021-28325 | MED 6.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 62.1% | — |
| CVE-2021-28323 | MED 6.5 | microsoft windows_10 Windows DNS Information Disclosure Vulnerability | 4.3% | — |
| CVE-2021-28311 | MED 6.5 | microsoft windows_10 Windows Application Compatibility Cache Denial of Service Vulnerability | 2.5% | — |
| CVE-2021-28039 | MED 6.5 | linux linux_kernel An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical | 0.4% | — |
| CVE-2021-28038 | MED 6.5 | debian debian_linux An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host | 0.7% | — |
| CVE-2021-27067 | MED 6.5 | microsoft azure_devops_server Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability | 2.6% | — |
| CVE-2021-26920 | MED 6.5 | apache druid In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of th | 9.5% | — |
| CVE-2021-26559 | MED 6.5 | apache airflow Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg` | 2.8% | — |
| CVE-2021-26421 | MED 6.5 | microsoft lync_server Skype for Business and Lync Spoofing Vulnerability | 1.4% | — |
| CVE-2021-26111 | MED 6.5 | fortinet fortiswitch A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below may allow an attacker on an adjacent network to exhaust available memory by sending specifically crafted LLDP/CDP | 0.4% | — |
| CVE-2021-25958 | MED 6.5 | apache ofbiz In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he | 2.6% | — |
| CVE-2021-24101 | MED 6.5 | microsoft dynamics_365 Microsoft Dataverse Information Disclosure Vulnerability | 3.1% | — |
| CVE-2021-24099 | MED 6.5 | microsoft lync_server Skype for Business and Lync Denial of Service Vulnerability | 3.2% | — |
| CVE-2021-24085 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 4.6% | — |
| CVE-2021-24080 | MED 6.5 | microsoft windows_10 Windows Trust Verification API Denial of Service Vulnerability | 3.1% | — |
| CVE-2021-24073 | MED 6.5 | microsoft lync_server Skype for Business and Lync Spoofing Vulnerability | 1.8% | — |
| CVE-2021-24012 | MED 6.5 | fortinet fortios An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority. | 0.5% | — |
| CVE-2021-23055 | MED 6.5 | f5 nginx_ingress_controller On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evalua | 0.8% | — |
| CVE-2021-23043 | MED 6.5 | f5 big-ip_access_policy_manager On BIG-IP, on all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to access arbitrary files. Note: Software ve | 2.0% | — |
| CVE-2021-22920 | MED 6.5 | citrix application_delivery_management A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, co | 0.9% | — |
| CVE-2021-22097 | MED 6.5 | vmware spring_advanced_message_queuing_protocol In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util | 1.1% | — |