CVEs from 2021

4,807 normalized CVEs published or assigned in this year.

Total
4,807
critical
critical 280
high
high 1,018
medium
medium 1,175
low
low 138
% Critical
5.8%
% with KEV
4.4%
% with exploit
5.3%

Top products

  • simatic_wincc_runtime_advanced 28
  • office 13
  • primavera_gateway 10
  • weblogic_server 9
  • primavera_unifier 8
  • modicon_m340_bmxp342020 8
  • log4j 8
  • communications_unified_inventory_management 7
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-44228 critical 10.0 5y ago Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
CVE-2021-22205 critical 10.0 5y ago GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through Exi…
CVE-2021-42013 critical 10.0 5y ago It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Al…
CVE-2021-26086 unknown 2.5 2y ago Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.
CVE-2021-44529 unknown 2.5 2y ago Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
CVE-2021-27877 unknown 2.5 3y ago Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.
CVE-2021-27878 unknown 2.5 3y ago Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.
CVE-2021-27876 unknown 2.5 3y ago Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Ag…
CVE-2021-35587 unknown 2.5 4y ago Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.
CVE-2021-3493 unknown 2.5 4y ago The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.
CVE-2021-31166 unknown 2.5 4y ago Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
CVE-2021-21551 unknown 2.5 4y ago Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
CVE-2021-26085 unknown 2.5 4y ago Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
CVE-2021-42237 unknown 2.5 4y ago Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
CVE-2021-36934 unknown 2.5 4y ago If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.
CVE-2021-25296 unknown 2.5 4y ago Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-25298 unknown 2.5 4y ago Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-25297 unknown 2.5 4y ago Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-21975 unknown 2.5 4y ago Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to s…
CVE-2021-36260 unknown 2.5 5y ago A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
CVE-2021-45046 unknown 2.5 5y ago Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in…
CVE-2021-44077 unknown 2.5 5y ago Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution
CVE-2021-42321 unknown 2.5 5y ago An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
CVE-2021-40449 unknown 2.5 5y ago Unspecified vulnerability allows for an authenticated user to escalate privileges.
CVE-2021-34527 unknown 2.5 5y ago Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an atta…
CVE-2021-27065 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2021-31207 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
CVE-2021-1498 unknown 2.5 5y ago Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.
CVE-2021-38647 unknown 2.5 5y ago Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.
CVE-2021-34523 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-21972 unknown 2.5 5y ago VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrest…
CVE-2021-34473 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-1732 unknown 2.5 5y ago Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-40444 unknown 2.5 5y ago Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
CVE-2021-36942 unknown 2.5 5y ago Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to au…
CVE-2021-1675 unknown 2.5 5y ago Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-38648 unknown 2.5 5y ago Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
CVE-2021-21985 unknown 2.5 5y ago VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code executio…
CVE-2021-22005 unknown 2.5 5y ago VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.
CVE-2021-40539 unknown 2.5 5y ago Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
CVE-2021-26855 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2021-30657 unknown 2.5 5y ago Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks.
CVE-2021-26084 unknown 2.5 5y ago Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.
CVE-2021-42258 unknown 2.5 5y ago BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.
CVE-2021-1497 unknown 2.5 5y ago Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.
CVE-2021-22986 unknown 2.5 5y ago F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system co…
CVE-2021-35464 unknown 2.5 5y ago ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFram…
CVE-2021-22502 unknown 2.5 5y ago Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-39144 unknown 2.5 5y ago XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command o…
CVE-2021-3129 unknown 2.5 5y ago Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().
CVE-2021-43116 unknown 1.0 4y ago Use of Hard-coded Credentials in Nacos
CVE-2021-42697 unknown 1.0 4y ago Uncontrolled Recursion in Akka HTTP
CVE-2021-22145 unknown 1.0 4y ago Generation of Error Message Containing Sensitive Information in Elasticsearch
CVE-2021-38294 unknown 1.0 5y ago Command injection leading to Remote Code Execution in Apache Storm
CVE-2021-34429 unknown 1.0 5y ago Encoded URIs can access WEB-INF directory in Eclipse Jetty
CVE-2021-25646 unknown 1.0 5y ago Code injection in Apache Druid
CVE-2021-27850 unknown 1.0 5y ago Remote code execution in Apache Tapestry
CVE-2021-33561 unknown 1.0 5y ago Cross-site scripting in Shopizer
CVE-2021-33562 unknown 1.0 5y ago Cross-site scripting in Shopizer
CVE-2021-28164 unknown 1.0 5y ago Authorization Before Parsing and Canonicalization in jetty