CVEs from 2021

4,788 normalized CVEs published or assigned in this year.

Total
4,788
critical
critical 281
high
high 1,022
medium
medium 1,179
low
low 138
% Critical
5.9%
% with KEV
4.4%
% with exploit
5.3%

Top products

  • simatic_wincc_runtime_advanced 28
  • office 13
  • primavera_gateway 10
  • weblogic_server 9
  • primavera_unifier 8
  • modicon_m340_bmxp342020 8
  • log4j 8
  • mbed_tls 8
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-36260 unknown 2.5 5y ago A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
CVE-2021-3930 low 2.5 5y ago An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). …
CVE-2021-20257 low 2.5 5y ago An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized wi…
CVE-2021-45046 unknown 2.5 5y ago Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in…
CVE-2021-44077 unknown 2.5 5y ago Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution
CVE-2021-43668 low 2.5 5y ago Denial of Service in Go-Ethereum
CVE-2021-40449 unknown 2.5 5y ago Unspecified vulnerability allows for an authenticated user to escalate privileges.
CVE-2021-42321 unknown 2.5 5y ago An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
CVE-2021-3572 low 2.5 5y ago A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest…
CVE-2021-20266 low 2.5 5y ago RHSA-2021:4489: rpm security, bug fix, and enhancement update (Low)
CVE-2021-3200 low 2.5 5y ago Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c…
CVE-2021-20269 low 2.5 5y ago RHSA-2021:4404: kexec-tools security, bug fix, and enhancement update (Low)
CVE-2021-43566 low 2.5 5y ago RHBA-2021:4438: samba bug fix and enhancement update (Low)
CVE-2021-38648 unknown 2.5 5y ago Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
CVE-2021-30657 unknown 2.5 5y ago Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks.
CVE-2021-22986 unknown 2.5 5y ago F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system co…
CVE-2021-35464 unknown 2.5 5y ago ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFram…
CVE-2021-40539 unknown 2.5 5y ago Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
CVE-2021-22502 unknown 2.5 5y ago Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-34473 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-31207 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
CVE-2021-1732 unknown 2.5 5y ago Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-27065 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2021-22005 unknown 2.5 5y ago VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.
CVE-2021-21985 unknown 2.5 5y ago VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code executio…
CVE-2021-40444 unknown 2.5 5y ago Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
CVE-2021-36942 unknown 2.5 5y ago Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to au…
CVE-2021-34523 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-38647 unknown 2.5 5y ago Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.
CVE-2021-26855 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2021-1497 unknown 2.5 5y ago Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.
CVE-2021-1675 unknown 2.5 5y ago Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-42258 unknown 2.5 5y ago BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.
CVE-2021-26084 unknown 2.5 5y ago Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.
CVE-2021-34527 unknown 2.5 5y ago Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an atta…
CVE-2021-21972 unknown 2.5 5y ago VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrest…
CVE-2021-1498 unknown 2.5 5y ago Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.
CVE-2021-3828 low 2.5 5y ago nltk is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-37860 low 2.5 5y ago Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server
CVE-2021-40839 low 2.5 5y ago The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.
CVE-2021-25737 low 2.5 5y ago A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or …
CVE-2021-23437 low 2.5 5y ago The package pillow from 0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
CVE-2021-39144 unknown 2.5 5y ago XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command o…
CVE-2021-22918 low 2.5 5y ago Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whethe…
CVE-2021-3652 low 2.5 5y ago RHSA-2021:3079: 389-ds:1.4 security and bug fix update (Low)
CVE-2021-29063 low 2.5 5y ago A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 when the mpmathify function is called.
CVE-2021-32813 low 2.5 5y ago Header dropping in traefik in github.com/traefik/traefik
CVE-2021-36374 low 2.5 5y ago Improper Handling of Length Parameter Inconsistency in Apache Ant
CVE-2021-36373 low 2.5 5y ago Improper Handling of Length Parameter Inconsistency in Apache Ant
CVE-2021-21303 low 2.5 5y ago insufficient validation in helm
CVE-2021-29957 low 2.5 5y ago multiple issues in thunderbird
CVE-2021-29956 low 2.5 5y ago multiple issues in thunderbird
CVE-2021-31542 low 2.5 5y ago In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
CVE-2021-26813 low 2.5 5y ago markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or de…
CVE-2021-20201 low 2.5 5y ago RHSA-2021:1924: spice security update (Low)
CVE-2021-23239 low 2.5 5y ago The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled…
CVE-2021-23240 low 2.5 5y ago selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary …
CVE-2021-32618 low 2.5 5y ago The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained version of Flask-Security based on the 3.0.0 version of…
CVE-2021-27919 low 2.5 5y ago archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any fi…
CVE-2021-28658 low 2.5 5y ago In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were no…
CVE-2021-3129 unknown 2.5 5y ago Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().
CVE-2021-3281 low 2.5 5y ago In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal …
CVE-2021-21330 low 2.5 5y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based…
CVE-2021-21236 low 2.5 6y ago CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When process…
CVE-2021-22054 unknown 1.5 3mo ago Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send …
CVE-2021-22681 unknown 1.5 3mo ago Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controll…
CVE-2021-22175 unknown 1.5 4mo ago GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
CVE-2021-26828 unknown 1.5 6mo ago OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
CVE-2021-26829 unknown 1.5 6mo ago OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.
CVE-2021-43226 unknown 1.5 8mo ago Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.
CVE-2021-32030 unknown 1.5 1y ago ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The impacted products c…
CVE-2021-20035 unknown 1.5 1y ago SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, whic…
CVE-2021-44207 unknown 1.5 2y ago Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be …
CVE-2021-40407 unknown 1.5 2y ago Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.
CVE-2021-41277 unknown 1.5 2y ago Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.
CVE-2021-20124 unknown 1.5 2y ago Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download a…
CVE-2021-20123 unknown 1.5 2y ago Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the un…
CVE-2021-33044 unknown 1.5 2y ago Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication.
CVE-2021-31196 unknown 1.5 2y ago Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.
CVE-2021-33045 unknown 1.5 2y ago Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.
CVE-2021-40655 unknown 1.5 2y ago D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page.
CVE-2021-36380 unknown 1.5 2y ago Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in …
CVE-2021-29256 unknown 1.5 3y ago Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.
CVE-2021-25395 unknown 1.5 3y ago Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.
CVE-2021-25489 unknown 1.5 3y ago Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic.
CVE-2021-25372 unknown 1.5 3y ago Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access.
CVE-2021-25394 unknown 1.5 3y ago Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.
CVE-2021-25487 unknown 1.5 3y ago Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution…
CVE-2021-25371 unknown 1.5 3y ago Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP.
CVE-2021-44026 unknown 1.5 3y ago Roundcube Webmail is vulnerable to SQL injection via search or search_params.
CVE-2021-30900 unknown 1.5 3y ago Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges.
CVE-2021-25370 unknown 1.5 4y ago Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. …
CVE-2021-25369 unknown 1.5 4y ago Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This …
CVE-2021-25337 unknown 1.5 4y ago Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with …
CVE-2021-31010 unknown 1.5 4y ago In affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions.
CVE-2021-38406 unknown 1.5 4y ago Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) resulting in an out-of-bounds write that allows for code exec…
CVE-2021-30983 unknown 1.5 4y ago Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges.
CVE-2021-38163 unknown 1.5 4y ago SAP NetWeaver contains a vulnerability that allows unrestricted file upload.
CVE-2021-30883 unknown 1.5 4y ago Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution.
CVE-2021-1048 unknown 1.5 4y ago Android kernel contains a use-after-free vulnerability that allows for privilege escalation.