CVEs from 2021
Total
4,788
critical
critical 281
high
high 1,022
medium
medium 1,179
low
low 138
% Critical
5.9%
% with KEV
4.4%
% with exploit
5.3%
Top vendors
Top products
- simatic_wincc_runtime_advanced 28
- office 13
- primavera_gateway 10
- weblogic_server 9
- primavera_unifier 8
- modicon_m340_bmxp342020 8
- log4j 8
- mbed_tls 8
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-32824 | unknown | — | — | 4y ago | Apache Dubbo vulnerable to remote code execution via Telnet Handler | |||
| CVE-2021-37533 | unknown | — | — | 4y ago | Apache Commons Net vulnerable to information leakage via malicious server | |||
| CVE-2021-42010 | unknown | — | — | 4y ago | Heron allows CRLF log injection | |||
| CVE-2021-43980 | unknown | — | — | 4y ago | The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in … | |||
| CVE-2021-43565 | unknown | — | — | 4y ago | The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server. | |||
| CVE-2021-3856 | unknown | — | — | 4y ago | Keycloak has Files or Directories Accessible to External Parties | |||
| CVE-2021-3644 | unknown | — | — | 4y ago | wildfly-core allows user with access to management interface to access vault expression, retrieve item from vault | |||
| CVE-2021-25642 | unknown | — | — | 4y ago | Deserialization of Untrusted Data in Apache Hadoop YARN | |||
| CVE-2021-42521 | unknown | — | — | 4y ago | There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', … | |||
| CVE-2021-3914 | unknown | — | — | 4y ago | SmallRye Health UI Cross-site Scripting vulnerability | |||
| CVE-2021-4040 | unknown | — | — | 4y ago | org.apache.activemq:artemis-core-client Vulnerable to Out-of-Bounds Write | |||
| CVE-2021-34538 | unknown | — | — | 4y ago | Apache Hive before 3.1.3 `CREATE` and `DROP` function operations do not check for necessary authorization. | |||
| CVE-2021-3859 | unknown | — | — | 4y ago | Undertow vulnerable to Denial of Service (DoS) attacks | |||
| CVE-2021-3690 | unknown | — | — | 4y ago | Undertow vulnerable to memory exhaustion due to buffer leak | |||
| CVE-2021-4178 | unknown | — | — | 4y ago | fabric8 kubernetes-client vulnerable | |||
| CVE-2021-44791 | unknown | — | — | 4y ago | Apache Druid before 0.23.0 vulnerable to reflected XSS via unescaped URL parameters | |||
| CVE-2021-41042 | unknown | — | — | 4y ago | XML External Entity Reference in Eclipse Lyo | |||
| CVE-2021-41411 | unknown | — | — | 4y ago | XML External Entity Reference in drools | |||
| CVE-2021-33036 | unknown | — | — | 4y ago | User account escalation in Apache Hadoop | |||
| CVE-2021-40660 | unknown | — | — | 4y ago | Regular expression denial of service in Delight Nashorn Sandbox | |||
| CVE-2021-37404 | unknown | — | — | 4y ago | Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2 | |||
| CVE-2021-3629 | unknown | — | — | 4y ago | Undertow Uncontrolled Resource Consumption | |||
| CVE-2021-3717 | unknown | — | — | 4y ago | Wildfly-Core user account mismanagement | |||
| CVE-2021-3597 | unknown | — | — | 4y ago | undertow Race Condition vulnerability | |||
| CVE-2021-33322 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP fails to invalidate password reset tokens after use | |||
| CVE-2021-20328 | unknown | — | — | 4y ago | Improper Certificate Validation in MongoDB | |||
| CVE-2021-33330 | unknown | — | — | 4y ago | Exposure of Resource to Wrong Sphere in Liferay Portal | |||
| CVE-2021-29049 | unknown | — | — | 4y ago | Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the currentURL Parameter | |||
| CVE-2021-21662 | unknown | — | — | 4y ago | Missing permission check in Jenkins XebiaLabs XL Deploy Plugin allows enumerating credentials IDs | |||
| CVE-2021-43576 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins pom2config Plugin | |||
| CVE-2021-21700 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins Scriptler Plugin | |||
| CVE-2021-21701 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins Performance Plugin | |||
| CVE-2021-43578 | unknown | — | — | 4y ago | Agent-to-controller security bypass in Jenkins Squash TM Publisher (Squash4Jenkins) Plugin allows writing arbitrary files | |||
| CVE-2021-21699 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins Active Choices Plugin | |||
| CVE-2021-43577 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins OWASP Dependency-Check Plugin | |||
| CVE-2021-21698 | unknown | — | — | 4y ago | Path traversal vulnerability in Jenkins Subversion Plugin allows reading arbitrary files | |||
| CVE-2021-22096 | unknown | — | — | 4y ago | Improper Output Neutralization for Logs in Spring Framework | |||
| CVE-2021-22044 | unknown | — | — | 4y ago | Exposure of Resource to Wrong Sphere in Spring Cloud OpenFeign | |||
| CVE-2021-22097 | unknown | — | — | 4y ago | Deserialization of Untrusted Data in Spring AMQP | |||
| CVE-2021-22047 | unknown | — | — | 4y ago | Exposure of Resource to Wrong Sphere in Spring Data REST | |||
| CVE-2021-2471 | unknown | — | — | 4y ago | Incorrect Authorization in MySQL Connector Java | |||
| CVE-2021-3869 | unknown | — | — | 4y ago | Improper Restriction of XML External Entity Reference in Stanford CoreNLP | |||
| CVE-2021-3878 | unknown | — | — | 4y ago | Improper Restriction of XML External Entity Reference in Stanford CoreNLP | |||
| CVE-2021-21684 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins Git Plugin | |||
| CVE-2021-40824 | unknown | — | — | 4y ago | Logic error in Matrix SDK for Android | |||
| CVE-2021-40797 | unknown | — | — | 4y ago | An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authentic… | |||
| CVE-2021-21678 | unknown | — | — | 4y ago | Jenkins SAML Plugin allows bypassing CSRF protection for any URL | |||
| CVE-2021-21680 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins Nested View Plugin | |||
| CVE-2021-21679 | unknown | — | — | 4y ago | Jenkins Azure AD Plugin allows bypassing CSRF protection for any URL | |||
| CVE-2021-21681 | unknown | — | — | 4y ago | Password stored in plain text by Jenkins Nomad Plugin | |||
| CVE-2021-21677 | unknown | — | — | 4y ago | RCE vulnerability in Jenkins Code Coverage API Plugin | |||
| CVE-2021-40085 | unknown | — | — | 4y ago | An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value. | |||
| CVE-2021-38598 | unknown | — | — | 4y ago | OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending c… | |||
| CVE-2021-28490 | unknown | — | — | 4y ago | Cross-Site Request Forgery in OWASP CSRFGuard | |||
| CVE-2021-38155 | unknown | — | — | 4y ago | OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). … | |||
| CVE-2021-3642 | unknown | — | — | 4y ago | Observable Discrepancy in Wildfly Elytron | |||
| CVE-2021-33335 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers | |||
| CVE-2021-33338 | unknown | — | — | 4y ago | Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs | |||
| CVE-2021-33336 | unknown | — | — | 4y ago | Liferay Portal Journal Module and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) | |||
| CVE-2021-33339 | unknown | — | — | 4y ago | Liferay Portal Fragment Module and Liferay DXP Vulnerable to Cross-Site Scripting | |||
| CVE-2021-33337 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Document Library module | |||
| CVE-2021-35463 | unknown | — | — | 4y ago | Liferay Portal cross-site scripting (XSS) vulnerability in the Frontend Taglib module | |||
| CVE-2021-33323 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP autosaves form data for other users to see | |||
| CVE-2021-33324 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Don't Check Permissions of Pages | |||
| CVE-2021-33320 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP vulnerable to email spam via lack of flagging rate | |||
| CVE-2021-33328 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Edit Vocabulary Page | |||
| CVE-2021-33326 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Frontend JS module | |||
| CVE-2021-33321 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP insecure default configuration | |||
| CVE-2021-33325 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Stores User Passwords in Cleartext | |||
| CVE-2021-33332 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) | |||
| CVE-2021-33333 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Fails to Check User Permissions for Workflow Submissions | |||
| CVE-2021-33334 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Fails to Properly Check User Permissions | |||
| CVE-2021-33331 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Allows Arbitrary Redirect of Users to External URLs | |||
| CVE-2021-34802 | unknown | — | — | 4y ago | Improper Privilege Management in Neo4j Graph Database | |||
| CVE-2021-21675 | unknown | — | — | 4y ago | CSRF vulnerabilities in Jenkins requests-plugin Plugin | |||
| CVE-2021-21674 | unknown | — | — | 4y ago | Missing permission check in Jenkins requests-plugin Plugin allows viewing pending requests | |||
| CVE-2021-21676 | unknown | — | — | 4y ago | Missing permission check in Jenkins requests-plugin Plugin allows sending emails | |||
| CVE-2021-21673 | unknown | — | — | 4y ago | Open redirect vulnerability in Jenkins CAS Plugin | |||
| CVE-2021-31649 | unknown | — | — | 4y ago | JFinal Java Deserialization Vulnerability | |||
| CVE-2021-21669 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins Generic Webhook Trigger Plugin | |||
| CVE-2021-21663 | unknown | — | — | 4y ago | Missing permission check in Jenkins XebiaLabs XL Deploy Plugin allows capturing credentials | |||
| CVE-2021-21665 | unknown | — | — | 4y ago | CSRF vulnerability in Jenkins XebiaLabs XL Deploy Plugin allows capturing credentials | |||
| CVE-2021-21664 | unknown | — | — | 4y ago | Incorrect permission check in XebiaLabs XL Deploy Plugin allows capturing credentials | |||
| CVE-2021-20267 | unknown | — | — | 4y ago | A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersona… | |||
| CVE-2021-22118 | unknown | — | — | 4y ago | Improper Privilege Management in Spring Framework | |||
| CVE-2021-33194 | unknown | — | — | 4y ago | golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input. | |||
| CVE-2021-21659 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins URLTrigger Plugin | |||
| CVE-2021-23937 | unknown | — | — | 4y ago | DNS based denial of service in Apache Wicket | |||
| CVE-2021-21658 | unknown | — | — | 4y ago | XML external entity vulnerability in Jenkins Nuget Plugin | |||
| CVE-2021-21660 | unknown | — | — | 4y ago | XSS vulnerability in Jenkins Markdown Formatter Plugin | |||
| CVE-2021-21657 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins Filesystem Trigger Plugin | |||
| CVE-2021-25934 | unknown | — | — | 4y ago | OpenNMS Horizon vulnerable to XSS | |||
| CVE-2021-29053 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Multiple SQL Injections | |||
| CVE-2021-29044 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Membership Request Admin Page | |||
| CVE-2021-29045 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the Redirect's Admin Page | |||
| CVE-2021-29046 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Asset Module Parameter | |||
| CVE-2021-29048 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in the Layout Admin Page | |||
| CVE-2021-29043 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password | |||
| CVE-2021-29051 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Asset Publisher App | |||
| CVE-2021-29052 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Fails to Check Permissions |