CVEs from 2021

4,786 normalized CVEs published or assigned in this year.

Total
4,786
critical
critical 281
high
high 1,022
medium
medium 1,179
low
low 138
% Critical
5.9%
% with KEV
4.5%
% with exploit
5.3%

Top products

  • simatic_wincc_runtime_advanced 28
  • office 13
  • primavera_gateway 10
  • weblogic_server 9
  • primavera_unifier 8
  • modicon_m340_bmxp342020 8
  • log4j 8
  • mbed_tls 8
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-47095 unknown In the Linux kernel, the following vulnerability has been resolved: ipmi: ssif: initialize ssif_info->client early During probe ssif_info->client is dereferenced in error path. However, it is set w…
CVE-2021-47102 unknown In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix incorrect structure access In line: upper = info->upper_dev; We access upper_dev field, which is rel…
CVE-2021-47113 unknown In the Linux kernel, the following vulnerability has been resolved: btrfs: abort in rename_exchange if we fail to insert the second ref Error injection stress uncovered a problem where we'd leave a…
CVE-2021-47104 unknown In the Linux kernel, the following vulnerability has been resolved: IB/qib: Fix memory leak in qib_user_sdma_queue_pkts() The wrong goto label was used for the error case and missed cleanup of the …
CVE-2021-47105 unknown In the Linux kernel, the following vulnerability has been resolved: ice: xsk: return xsk buffers back to pool when cleaning the ring Currently we only NULL the xdp_buff pointer in the internal SW r…
CVE-2021-47109 unknown In the Linux kernel, the following vulnerability has been resolved: neighbour: allow NUD_NOARP entries to be forced GCed IFF_POINTOPOINT interfaces use NUD_NOARP entries for IPv6. It's possible to …
CVE-2021-47108 unknown In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: hdmi: Perform NULL pointer check for mtk_hdmi_conf In commit 41ca9caaae0b ("drm/mediatek: hdmi: Add check for CEA m…
CVE-2021-47111 unknown In the Linux kernel, the following vulnerability has been resolved: xen-netback: take a reference to the RX task thread Do this in order to prevent the task from being freed if the thread returns (…
CVE-2021-47117 unknown In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug on in ext4_es_cache_extent as ext4_split_extent_at failed We got follow bug_on when run fsstress with injecting IO …
CVE-2021-47114 unknown In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix data corruption by fallocate When fallocate punches holes out of inode size, if original isize is in the middle of las…
CVE-2021-47116 unknown In the Linux kernel, the following vulnerability has been resolved: ext4: fix memory leak in ext4_mb_init_backend on error path. Fix a memory leak discovered by syzbot when a file system is corrupt…
CVE-2021-47121 unknown In the Linux kernel, the following vulnerability has been resolved: net: caif: fix memory leak in cfusbl_device_notify In case of caif_enroll_dev() fail, allocated link_support won't be assigned to…
CVE-2021-47122 unknown In the Linux kernel, the following vulnerability has been resolved: net: caif: fix memory leak in caif_device_notify In case of caif_enroll_dev() fail, allocated link_support won't be assigned to t…
CVE-2021-47135 unknown In the Linux kernel, the following vulnerability has been resolved: mt76: mt7921: fix possible AOOB issue in mt7921_mcu_tx_rate_report Fix possible array out of bound access in mt7921_mcu_tx_rate_r…
CVE-2021-47123 unknown In the Linux kernel, the following vulnerability has been resolved: io_uring: fix ltout double free on completion race Always remove linked timeout on io_link_timeout_fn() from the master request l…
CVE-2021-47126 unknown In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix KASAN: slab-out-of-bounds Read in fib6_nh_flush_exceptions Reported by syzbot: HEAD commit: 90c911ad Merge tag 'fixe…
CVE-2021-47129 unknown In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: skip expectations for confirmed conntrack nft_ct_expect_obj_eval() calls nf_ct_ext_add() for a confirmed connt…
CVE-2021-47130 unknown In the Linux kernel, the following vulnerability has been resolved: nvmet: fix freeing unallocated p2pmem In case p2p device was found but the p2p pool is empty, the nvme target is still trying to …
CVE-2021-47141 unknown In the Linux kernel, the following vulnerability has been resolved: gve: Add NULL pointer checks when freeing irqs. When freeing notification blocks, we index priv->msix_vectors. If we failed to al…
CVE-2021-47132 unknown In the Linux kernel, the following vulnerability has been resolved: mptcp: fix sk_forward_memory corruption on retransmission MPTCP sk_forward_memory handling is a bit special, as such field is pro…
CVE-2021-47142 unknown In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix a use-after-free looks like we forget to set ttm->sg to NULL. Hit panic below [ 1235.844104] general protection …
CVE-2021-47134 unknown In the Linux kernel, the following vulnerability has been resolved: efi/fdt: fix panic when no valid fdt found setup_arch() would invoke efi_init()->efi_get_fdt_params(). If no valid fdt found then…
CVE-2021-47138 unknown In the Linux kernel, the following vulnerability has been resolved: cxgb4: avoid accessing registers when clearing filters Hardware register having the server TID base can contain invalid values wh…
CVE-2021-47143 unknown In the Linux kernel, the following vulnerability has been resolved: net/smc: remove device from smcd_dev_list after failed device_add() If the device_add() for a smcd_dev fails, there's no cleanup …
CVE-2021-47145 unknown In the Linux kernel, the following vulnerability has been resolved: btrfs: do not BUG_ON in link_to_fixup_dir While doing error injection testing I got the following panic kernel BUG at fs/btrfs…
CVE-2021-46747 unknown 6d ago Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System Management Network) apertures lead…
CVE-2021-47621 unknown 2y ago ClassGraph XML External Entity Reference
CVE-2021-3754 unknown 2y ago Keycloak's improper input validation allows using email as username
CVE-2021-22573 unknown 2y ago google-oauth-java-client improperly verifies cryptographic signature
CVE-2021-28656 unknown 2y ago Apache Zeppelin CSRF vulnerability in the Credentials page
CVE-2021-29038 unknown 2y ago Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers
CVE-2021-29050 unknown 2y ago Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery in Terms of Use Page
CVE-2021-37942 unknown 3y ago APM Java Agent Local Privilege Escalation issue
CVE-2021-32050 unknown 3y ago Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data…
CVE-2021-28655 unknown 3y ago Apache Zeppelin Improper Input Validation vulnerability
CVE-2021-31635 unknown 3y ago jFinal Server-Side Template Injection vulnerability
CVE-2021-40331 unknown 3y ago Apache Ranger Hive Plugin missing permissions check
CVE-2021-28235 unknown 3y ago Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
CVE-2021-46877 unknown 3y ago jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonN…
CVE-2021-37305 unknown 3y ago Insecure Permissions issue in jeecg-boot
CVE-2021-37304 unknown 3y ago Insecure Permissions issue in jeecg-boot
CVE-2021-37306 unknown 3y ago Insecure Permissions issue in jeecg-boot
CVE-2021-32828 unknown 4y ago Nuxeo vulnerable to Reflected Cross-Site Scripting leading to Remote Code Execution
CVE-2021-32824 unknown 4y ago Apache Dubbo vulnerable to remote code execution via Telnet Handler
CVE-2021-37533 unknown 4y ago Apache Commons Net vulnerable to information leakage via malicious server
CVE-2021-42010 unknown 4y ago Heron allows CRLF log injection
CVE-2021-43980 unknown 4y ago The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in …
CVE-2021-43565 unknown 4y ago The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.
CVE-2021-3856 unknown 4y ago Keycloak has Files or Directories Accessible to External Parties
CVE-2021-3644 unknown 4y ago wildfly-core allows user with access to management interface to access vault expression, retrieve item from vault
CVE-2021-25642 unknown 4y ago Deserialization of Untrusted Data in Apache Hadoop YARN
CVE-2021-42521 unknown 4y ago There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', …
CVE-2021-3914 unknown 4y ago SmallRye Health UI Cross-site Scripting vulnerability
CVE-2021-4040 unknown 4y ago org.apache.activemq:artemis-core-client Vulnerable to Out-of-Bounds Write
CVE-2021-34538 unknown 4y ago Apache Hive before 3.1.3 `CREATE` and `DROP` function operations do not check for necessary authorization.
CVE-2021-3859 unknown 4y ago Undertow vulnerable to Denial of Service (DoS) attacks
CVE-2021-3690 unknown 4y ago Undertow vulnerable to memory exhaustion due to buffer leak
CVE-2021-4178 unknown 4y ago fabric8 kubernetes-client vulnerable
CVE-2021-44791 unknown 4y ago Apache Druid before 0.23.0 vulnerable to reflected XSS via unescaped URL parameters
CVE-2021-41042 unknown 4y ago XML External Entity Reference in Eclipse Lyo
CVE-2021-41411 unknown 4y ago XML External Entity Reference in drools
CVE-2021-33036 unknown 4y ago User account escalation in Apache Hadoop
CVE-2021-40660 unknown 4y ago Regular expression denial of service in Delight Nashorn Sandbox
CVE-2021-37404 unknown 4y ago Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2
CVE-2021-3629 unknown 4y ago Undertow Uncontrolled Resource Consumption
CVE-2021-3717 unknown 4y ago Wildfly-Core user account mismanagement
CVE-2021-3597 unknown 4y ago undertow Race Condition vulnerability
CVE-2021-33322 unknown 4y ago Liferay Portal and Liferay DXP fails to invalidate password reset tokens after use
CVE-2021-20328 unknown 4y ago Improper Certificate Validation in MongoDB
CVE-2021-33330 unknown 4y ago Exposure of Resource to Wrong Sphere in Liferay Portal
CVE-2021-29049 unknown 4y ago Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the currentURL Parameter
CVE-2021-21662 unknown 4y ago Missing permission check in Jenkins XebiaLabs XL Deploy Plugin allows enumerating credentials IDs
CVE-2021-43576 unknown 4y ago XXE vulnerability in Jenkins pom2config Plugin
CVE-2021-21700 unknown 4y ago Stored XSS vulnerability in Jenkins Scriptler Plugin
CVE-2021-43578 unknown 4y ago Agent-to-controller security bypass in Jenkins Squash TM Publisher (Squash4Jenkins) Plugin allows writing arbitrary files
CVE-2021-21701 unknown 4y ago XXE vulnerability in Jenkins Performance Plugin
CVE-2021-43577 unknown 4y ago XXE vulnerability in Jenkins OWASP Dependency-Check Plugin
CVE-2021-21699 unknown 4y ago Stored XSS vulnerability in Jenkins Active Choices Plugin
CVE-2021-21698 unknown 4y ago Path traversal vulnerability in Jenkins Subversion Plugin allows reading arbitrary files
CVE-2021-22096 unknown 4y ago Improper Output Neutralization for Logs in Spring Framework
CVE-2021-22047 unknown 4y ago Exposure of Resource to Wrong Sphere in Spring Data REST
CVE-2021-22097 unknown 4y ago Deserialization of Untrusted Data in Spring AMQP
CVE-2021-22044 unknown 4y ago Exposure of Resource to Wrong Sphere in Spring Cloud OpenFeign
CVE-2021-2471 unknown 4y ago Incorrect Authorization in MySQL Connector Java
CVE-2021-3869 unknown 4y ago Improper Restriction of XML External Entity Reference in Stanford CoreNLP
CVE-2021-3878 unknown 4y ago Improper Restriction of XML External Entity Reference in Stanford CoreNLP
CVE-2021-21684 unknown 4y ago Stored XSS vulnerability in Jenkins Git Plugin
CVE-2021-40824 unknown 4y ago Logic error in Matrix SDK for Android
CVE-2021-40797 unknown 4y ago An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authentic…
CVE-2021-21678 unknown 4y ago Jenkins SAML Plugin allows bypassing CSRF protection for any URL
CVE-2021-21677 unknown 4y ago RCE vulnerability in Jenkins Code Coverage API Plugin
CVE-2021-21679 unknown 4y ago Jenkins Azure AD Plugin allows bypassing CSRF protection for any URL
CVE-2021-21681 unknown 4y ago Password stored in plain text by Jenkins Nomad Plugin
CVE-2021-21680 unknown 4y ago XXE vulnerability in Jenkins Nested View Plugin
CVE-2021-40085 unknown 4y ago An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.
CVE-2021-38598 unknown 4y ago OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending c…
CVE-2021-28490 unknown 4y ago Cross-Site Request Forgery in OWASP CSRFGuard
CVE-2021-38155 unknown 4y ago OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). …
CVE-2021-33335 unknown 4y ago Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers
CVE-2021-3642 unknown 4y ago Observable Discrepancy in Wildfly Elytron