CVEs from 2021
Total
4,791
critical
critical 281
high
high 1,022
medium
medium 1,179
low
low 138
% Critical
5.9%
% with KEV
4.4%
% with exploit
5.3%
Top vendors
Top products
- simatic_wincc_runtime_advanced 28
- office 13
- primavera_gateway 10
- weblogic_server 9
- primavera_unifier 8
- modicon_m340_bmxp342020 8
- log4j 8
- mbed_tls 8
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-22792 | high | 7.5 | 7.5 | 5y ago | A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted proj… | |||
| CVE-2021-38202 | high | 7.5 | 7.5 | 5y ago | fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is bei… | |||
| CVE-2021-22926 | high | 7.5 | 7.5 | 5y ago | libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is bui… | |||
| CVE-2021-22766 | high | 7.5 | 7.5 | 5y ago | A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service via a specially crafte… | |||
| CVE-2021-32926 | high | 7.5 | 7.5 | 5y ago | When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includes the legitimate, new password hash and replace it with an … | |||
| CVE-2021-27386 | high | 7.5 | 7.5 | 5y ago | A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (in… | |||
| CVE-2021-27385 | high | 7.5 | 7.5 | 5y ago | A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (in… | |||
| CVE-2021-27383 | high | 7.5 | 7.5 | 5y ago | A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (in… | |||
| CVE-2021-25662 | high | 7.5 | 7.5 | 5y ago | A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (in… | |||
| CVE-2021-25661 | high | 7.5 | 7.5 | 5y ago | A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (in… | |||
| CVE-2021-25660 | high | 7.5 | 7.5 | 5y ago | A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (in… | |||
| CVE-2021-29241 | high | 7.5 | 7.5 | 5y ago | CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS). | |||
| CVE-2021-22713 | high | 7.5 | 7.5 | 5y ago | A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security … | |||
| CVE-2021-22703 | high | 7.5 | 7.5 | 5y ago | A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affec… | |||
| CVE-2021-22702 | high | 7.5 | 7.5 | 5y ago | A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/73xx, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notifica… | |||
| CVE-2021-47975 | high | 7.2 | 7.2 | 21d ago | WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the `fieldtitle` parameter. Attackers can submit … | |||
| CVE-2021-47963 | high | 7.2 | 7.2 | 22d ago | Anote 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to execute arbitrary code by injecting malicious payloads into markdown files stored within the application. A… | |||
| CVE-2021-36898 | high | 7.2 | 7.2 | 4y ago | Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress. | |||
| CVE-2021-47980 | high | 7.1 | 7.1 | 21d ago | Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'col' parameter in the Activity Log i… | |||
| CVE-2021-4090 | high | 7.1 | 7.1 | 4y ago | An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw… | |||
| CVE-2021-36133 | high | 7.1 | 7.1 | 5y ago | The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/wr… | |||
| CVE-2021-41617 | high | 7.0 | 7.0 | 5y ago | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs … | |||
| CVE-2021-36368 | low | 3.7 | 3.7 | 4y ago | An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to… | |||
| CVE-2021-21300 | low | — | 3.5 | — | Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as… | |||
| CVE-2021-25740 | low | 3.1 | 3.1 | 5y ago | A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. | |||
| CVE-2021-37616 | low | — | 2.5 | — | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. … | |||
| CVE-2021-3476 | low | — | 2.5 | — | A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially aff… | |||
| CVE-2021-3478 | low | — | 2.5 | — | There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory… | |||
| CVE-2021-36690 | low | — | 2.5 | — | A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance o… | |||
| CVE-2021-37615 | low | — | 2.5 | — | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. … | |||
| CVE-2021-22222 | low | — | 2.5 | — | Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-39929 | low | — | 2.5 | — | Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-32707 | low | — | 2.5 | — | information disclosure in nextcloud-app-mail | |||
| CVE-2021-20177 | low | — | 2.5 | — | A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root or CAP_NET_ADMIN) when inserting iptables rules could insert a rule which can pa… | |||
| CVE-2021-22235 | low | — | 2.5 | — | Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-22207 | low | — | 2.5 | — | Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-22173 | low | — | 2.5 | — | Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-34183 | low | — | 2.5 | — | denial of service in imagemagick | |||
| CVE-2021-32275 | low | — | 2.5 | — | An issue was discovered in faust through v2.30.5. A NULL pointer dereference exists in the function CosPrim::computeSigOutput() located in cosprim.hh. It allows an attacker to cause Denial of Service. | |||
| CVE-2021-39220 | low | — | 2.5 | — | information disclosure in nextcloud-app-mail | |||
| CVE-2021-39247 | low | — | 2.5 | — | Zint Barcode Generator before 2.10.0 has a one-byte buffer over-read, related to is_last_single_ascii in code1.c, and rs_encode_uint in reedsol.c. | |||
| CVE-2021-32815 | low | — | 2.5 | — | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The assertion failure is triggered when Exiv2 is used to modify the metadata… | |||
| CVE-2021-3658 | low | — | 2.5 | — | bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discov… | |||
| CVE-2021-42917 | low | — | 2.5 | — | Buffer overflow vulnerability in Kodi xbmc up to 19.0, allows attackers to cause a denial of service due to improper length of values passed to istream. | |||
| CVE-2021-43877 | low | — | 2.5 | — | privilege escalation in dotnet-runtime | |||
| CVE-2021-37623 | low | — | 2.5 | — | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infini… | |||
| CVE-2021-39928 | low | — | 2.5 | — | NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-3474 | low | — | 2.5 | — | There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with app… | |||
| CVE-2021-27375 | low | — | 2.5 | — | insufficient validation in traefik | |||
| CVE-2021-3467 | low | — | 2.5 | — | denial of service in jasper | |||
| CVE-2021-39920 | low | — | 2.5 | — | NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-39921 | low | — | 2.5 | — | NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-39926 | low | — | 2.5 | — | Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-32613 | low | — | 2.5 | — | In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS. | |||
| CVE-2021-27212 | low | — | 2.5 | — | In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemo… | |||
| CVE-2021-30219 | low | — | 2.5 | — | denial of service in samurai | |||
| CVE-2021-32719 | low | — | 2.5 | — | cross-site scripting in rabbitmq | |||
| CVE-2021-32718 | low | — | 2.5 | — | cross-site scripting in rabbitmq | |||
| CVE-2021-4021 | low | — | 2.5 | — | A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled res… | |||
| CVE-2021-38373 | low | — | 2.5 | — | In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked. | |||
| CVE-2021-20189 | low | — | 2.5 | — | incorrect calculation in imagemagick | |||
| CVE-2021-28831 | low | — | 2.5 | — | decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data. | |||
| CVE-2021-34334 | low | — | 2.5 | — | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a c… | |||
| CVE-2021-3549 | low | — | 2.5 | — | An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a… | |||
| CVE-2021-22174 | low | — | 2.5 | — | Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-34813 | low | — | 2.5 | — | Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has … | |||
| CVE-2021-39924 | low | — | 2.5 | — | Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-3968 | low | — | 2.5 | — | vim is vulnerable to Heap-based Buffer Overflow | |||
| CVE-2021-39922 | low | — | 2.5 | — | Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-1252 | low | — | 2.5 | — | A vulnerability in the Excel XLM macro parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service con… | |||
| CVE-2021-36769 | low | — | 2.5 | — | content spoofing in telegram-desktop | |||
| CVE-2021-27815 | low | — | 2.5 | — | NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicio… | |||
| CVE-2021-33500 | low | — | 2.5 | — | PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its title repeatedly at high speed, which results in many SetW… | |||
| CVE-2021-36367 | low | — | 2.5 | — | PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a l… | |||
| CVE-2021-3479 | low | — | 2.5 | — | There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger excessive consumption o… | |||
| CVE-2021-1405 | low | — | 2.5 | — | A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service con… | |||
| CVE-2021-30178 | low | — | 2.5 | — | An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer dereference for certain accesses to the SynIC Hyper-V context, aka CID-919f4ebc5987. | |||
| CVE-2021-3927 | low | — | 2.5 | — | vim is vulnerable to Heap-based Buffer Overflow | |||
| CVE-2021-40985 | low | — | 2.5 | — | A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp. | |||
| CVE-2021-28117 | low | — | 2.5 | — | libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are neither https:// nor http://) based on the content of… | |||
| CVE-2021-20296 | low | — | 2.5 | — | A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could ca… | |||
| CVE-2021-3671 | low | — | 2.5 | — | A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samb… | |||
| CVE-2021-20217 | low | — | 2.5 | — | A flaw was found in Privoxy in versions before 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service. The highest threat from this vulnerability is to system a… | |||
| CVE-2021-3477 | low | — | 2.5 | — | There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer over… | |||
| CVE-2021-39925 | low | — | 2.5 | — | Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-3973 | low | — | 2.5 | — | vim is vulnerable to Heap-based Buffer Overflow | |||
| CVE-2021-34335 | low | — | 2.5 | — | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A floating point exception (FPE) due to an integer divide by zero was found … | |||
| CVE-2021-37621 | low | — | 2.5 | — | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infini… | |||
| CVE-2021-3974 | low | — | 2.5 | — | vim is vulnerable to Use After Free | |||
| CVE-2021-20193 | low | — | 2.5 | — | A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat fro… | |||
| CVE-2021-28090 | low | — | 2.5 | — | Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002. | |||
| CVE-2021-28089 | low | — | 2.5 | — | Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001. | |||
| CVE-2021-3673 | low | — | 2.5 | — | A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and DoS. | |||
| CVE-2021-41865 | low | — | 2.5 | — | denial of service in nomad | |||
| CVE-2021-4023 | low | — | 2.5 | — | A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-urin… | |||
| CVE-2021-30046 | low | — | 2.5 | — | denial of service in vigra | |||
| CVE-2021-35331 | low | — | 2.5 | — | In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding | |||
| CVE-2021-3443 | low | — | 2.5 | — | denial of service in jasper | |||
| CVE-2021-20216 | low | — | 2.5 | — | A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is t… | |||
| CVE-2021-37620 | low | — | 2.5 | — | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The o… |