Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
2 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
2109
Current result set after filter and search.
Exploited Flagged
1998
Rows with a non-empty exploitation signal.
Distinct CWE
1
Unique weakness classes in this view.
Modules
592
Unique inferred driver or component labels.
Reset
Active filters CWE Unspecified Clear filters

Top CWE

1 classes
Release Month
September 2021
13 CVE | last update 2 day(s) ago
Release 2021-09-14 Patch Tuesday Count 12
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-38633
Windows Common Log File System Driver
Exploitation More Likely
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-09-14 No
CVE-2021-36963
Windows Common Log File System Driver
Exploitation More Likely
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-09-14 No
Reported By
CVE-2021-36955
Windows Common Log File System Driver
Exploitation More Likely
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
2021-09-14 No -
CVE-2021-36954
Windows Bind Filter Driver
Exploitation Less Likely
Windows Bind Filter Driver Elevation of Privilege Vulnerability
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-09-14 No
Reported By
k0shl of Kunlun Lab
CVE-2021-38638
Windows Ancillary Function Driver for WinSock
Exploitation Less Likely
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-09-14 No
CVE-2021-38629
Windows Ancillary Function Driver for WinSock
Exploitation Less Likely
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2021-09-14 No
CVE-2021-38628
Windows Ancillary Function Driver for WinSock
Exploitation Less Likely
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-09-14 No
CVE-2021-38639
Win32k
Exploitation More Likely
Win32k Elevation of Privilege Vulnerability
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-09-14 No
Reported By
RanchoIce of Singular Security Lab
CVE-2021-36975
Win32k
Exploitation More Likely
Win32k Elevation of Privilege Vulnerability
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-09-14 No
Reported By
Nguyen Phuong Nam
CVE-2021-38634
Microsoft Windows Update Client
Exploitation Less Likely
Microsoft Windows Update Client Elevation of Privilege Vulnerability
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C
2021-09-14 No
Reported By
Abdelhamid Naceri working with Trend Micro Zero Day Initiative
CVE-2021-38644
Microsoft MPEG-2 Video Extension
Exploitation Less Likely
Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-09-14 No
Reported By
HAO LI of VenusTech ADLab
CVE-2021-38661
HEVC Video Extensions
Exploitation Less Likely
HEVC Video Extensions Remote Code Execution Vulnerability
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-09-14 No
Reported By
Azure Yang with Cyber Kunlun Lab
Dhanesh Kizhakkinan of FireEye Inc.
crashman of codemize security research lab
Release 2021-09-07 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-40444
Microsoft MSHTML
Exploitation Detected
Microsoft MSHTML Remote Code Execution Vulnerability
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L/E:P/RL:O/RC:C
2021-09-07 Yes
Reported By
Bryce Abdo of Mandiant
Haifei Li of EXPMON
Genwei Jiang of Mandiant
Rick Cole (MSTIC)
Dhanesh Kizhakkinan of Mandiant
Release Month
August 2021
28 CVE | last update 2 day(s) ago
Release 2021-08-13 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-38199
fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering which allows operators of remote NFSv4 servers to cause a
No latest release note
fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.
CVSS vector: AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-08-13 - -
Release 2021-08-11 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-36958
Windows Print Spooler
Exploitation More Likely
Windows Print Spooler Remote Code Execution Vulnerability
No CVSS vector published
2021-08-11 No
Reported By
Victor Mata of FusionX, Accenture Security
Release 2021-08-10 Patch Tuesday Count 26
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-34484
Windows User Profile Service
Exploitation Less Likely
Windows User Profile Service Elevation of Privilege Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Abdelhamid Naceri (halov) working with Trend Micro Zero Day Initiative
CVE-2021-26426
Windows User Account Profile Picture
Exploitation Less Likely
Windows User Account Profile Picture Elevation of Privilege Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Abdelhamid Naceri (halov) working with Trend Micro Zero Day Initiative
CVE-2021-36948
Windows Update Medic Service
Exploitation Detected
Windows Update Medic Service Elevation of Privilege Vulnerability
No CVSS vector published
2021-08-10 Yes
Reported By
Microsoft Threat Intelligence Center (MSTIC)
Microsoft Security Response Center (MSRC)
CVE-2021-26424
Windows TCP/IP
Exploitation More Likely
Windows TCP/IP Remote Code Execution Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Quan Luo from Codesafe Team of Legendsec at Qi'anxin Group
CVE-2021-36933
Windows Services for NFS ONCRPC XDR Driver
Exploitation Less Likely
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Liubenjin with Codesafe Team of Legendsec at Qi'anxin Group
CVE-2021-36932
Windows Services for NFS ONCRPC XDR Driver
Exploitation Less Likely
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Liubenjin with Codesafe Team of Legendsec at Qi'anxin Group
CVE-2021-36926
Windows Services for NFS ONCRPC XDR Driver
Exploitation Less Likely
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Liubenjin from Codesafe Team of Legendsec at Qi'anxin Group
CVE-2021-26433
Windows Services for NFS ONCRPC XDR Driver
Exploitation Less Likely
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Liubenjin from Codesafe Team of Legendsec at Qi'anxin Group
CVE-2021-26432
Windows Services for NFS ONCRPC XDR Driver
Exploitation More Likely
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Liubenjin from Codesafe Team of Legendsec at Qi'anxin Group
CVE-2021-26431
Windows Recovery Environment Agent
Exploitation Less Likely
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Abdelhamid Naceri (halov) working with Trend Micro Zero Day Initiative
CVE-2021-36947
Windows Print Spooler
Exploitation More Likely
Windows Print Spooler Remote Code Execution Vulnerability
No CVSS vector published
2021-08-10 No -
CVE-2021-36936
Windows Print Spooler
Exploitation More Likely
Windows Print Spooler Remote Code Execution Vulnerability
No CVSS vector published
2021-08-10 No -
CVE-2021-34483
Windows Print Spooler
Exploitation Less Likely
Windows Print Spooler Elevation of Privilege Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Thibault van Geluwe
[Victor Mata](https://twitter.com/offenseindepth) of FusionX, Accenture Security
CVE-2021-36937
Windows Media MPEG-4 Video Decoder
Exploitation Less Likely
Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
HAO LI of VenusTech ADLab
crashman of codemize security research lab
CVE-2021-34534
Windows MSHTML Platform
Exploitation Less Likely
Windows MSHTML Platform Remote Code Execution Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
CVE-2021-34533
Windows Graphics Component Font Parsing
Exploitation Less Likely
Windows Graphics Component Font Parsing Remote Code Execution Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
HAO LI of VenusTech ADLab
CVE-2021-34530
Windows Graphics Component
Exploitation Less Likely
Windows Graphics Component Remote Code Execution Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Zhihua Yao of KunLun Lab
CVE-2021-34487
Windows Event Tracing
Exploitation Less Likely
Windows Event Tracing Elevation of Privilege Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Jacob Lewellen of Microsoft
CVE-2021-34486
Windows Event Tracing
Exploitation Less Likely
Windows Event Tracing Elevation of Privilege Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Yong Chuan Koh (@yongchuank)
CVE-2021-26425
Windows Event Tracing
Exploitation Less Likely
Windows Event Tracing Elevation of Privilege Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Abdelhamid Naceri (halov) working with Trend Micro Zero Day Initiative
CVE-2021-36927
Windows Digital TV Tuner device registration application
Exploitation Less Likely
Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
CVE-2021-36938
Windows Cryptographic Primitives Library
Exploitation Unlikely
Windows Cryptographic Primitives Library Information Disclosure Vulnerability
No CVSS vector published
2021-08-10 No -
CVE-2021-34537
Windows Bluetooth Driver
Exploitation Less Likely
Windows Bluetooth Driver Elevation of Privilege Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
ziming zhang of Ant Security Light-Year Lab
CVE-2021-36945
Windows 10 Update Assistant
Exploitation Less Likely
Windows 10 Update Assistant Elevation of Privilege Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Abdelhamid Naceri (halov) working with Trend Micro Zero Day Initiative
CVE-2021-34536
Storage Spaces Controller
Exploitation Less Likely
Storage Spaces Controller Elevation of Privilege Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
nghiadt12 (@nghiadt1098) from Viettel Cyber Security
Le Huu Quang Linh (@linhlhq) from Vietnam National Cyber ​​Security Center (NCSC Vietnam)
kpc working with Trend Micro Zero Day Initiative
CVE-2021-34535
Remote Desktop Client
Exploitation More Likely
Remote Desktop Client Remote Code Execution Vulnerability
No CVSS vector published
2021-08-10 No
Reported By
Malcolm Stagg
Release Month
July 2021
9 CVE | last update 2 day(s) ago
Release 2021-07-30 Other / OOB Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2014-7204
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a
No latest release note
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
No CVSS vector published
2021-07-30 - -
CVE-2019-2708
Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are Prior to 6.138 prior to 6.2.38 and prior to 18.1.32. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial
No latest release note
Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are Prior to 6.138 prior to 6.2.38 and prior to 18.1.32. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Data Store. CVSS 3.0 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
2021-07-30 - -
Release 2021-07-20 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-36934
Windows
Exploitation More Likely
Windows Elevation of Privilege Vulnerability
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:T/RC:C
2021-07-20 No -
Release 2021-07-15 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-34481
Windows Print Spooler
Exploitation More Likely
Windows Print Spooler Remote Code Execution Vulnerability
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
2021-07-15 No
Reported By
Release 2021-07-13 Patch Tuesday Count 5
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-34490
Windows TCP/IP Driver
Exploitation Less Likely
Windows TCP/IP Driver Denial of Service Vulnerability
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2021-07-13 No -
CVE-2021-33772
Windows TCP/IP Driver
Exploitation Less Likely
Windows TCP/IP Driver Denial of Service Vulnerability
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2021-07-13 No
Reported By
Polar Bear at Microsoft
CVE-2021-31183
Windows TCP/IP Driver
Exploitation Less Likely
Windows TCP/IP Driver Denial of Service Vulnerability
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2021-07-13 No -
CVE-2021-33783
Windows SMB
Exploitation Less Likely
Windows SMB Information Disclosure Vulnerability
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2021-07-13 No -
CVE-2021-34507
Windows Remote Assistance
Exploitation Less Likely
Windows Remote Assistance Information Disclosure Vulnerability
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2021-07-13 No
Reported By
Chris Alladoum of SophosLabs, Sophos Ltd
Tomer Bar @ SafeBreach and Eran Segal @ SafeBreach
Prev Page 18 / 43 | rows 851-900 of 2109 Next