CVEs from 2021

4,791 normalized CVEs published or assigned in this year.

Total
4,791
critical
critical 281
high
high 1,022
medium
medium 1,179
low
low 138
% Critical
5.9%
% with KEV
4.4%
% with exploit
5.3%

Top products

  • simatic_wincc_runtime_advanced 28
  • office 13
  • primavera_gateway 10
  • weblogic_server 9
  • primavera_unifier 8
  • modicon_m340_bmxp342020 8
  • log4j 8
  • mbed_tls 8
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-2163 medium 5.5 5y ago RHSA-2022:6735: java-1.8.0-ibm security update (Moderate)
CVE-2021-3115 medium 5.5 5y ago RHSA-2021:1746: go-toolset:rhel8 security, bug fix, and enhancement update (Moderate)
CVE-2021-23993 medium 5.5 5y ago RHSA-2021:1193: thunderbird security update (Moderate)
CVE-2021-29949 medium 5.5 5y ago RHSA-2021:1193: thunderbird security update (Moderate)
CVE-2021-23991 medium 5.5 5y ago RHSA-2021:1193: thunderbird security update (Moderate)
CVE-2021-29950 medium 5.5 5y ago RHSA-2021:1193: thunderbird security update (Moderate)
CVE-2021-23992 medium 5.5 5y ago RHSA-2021:1193: thunderbird security update (Moderate)
CVE-2021-3347 medium 5.5 5y ago An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1…
CVE-2021-20295 medium 5.5 5y ago It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-2020:4676) erratum released as part of Red Hat Enterprise Linux 8.3 failed to i…
CVE-2021-28965 medium 5.5 5y ago RHSA-2021:2588: ruby:2.6 security, bug fix, and enhancement update (Moderate)
CVE-2021-3447 medium 5.5 5y ago A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controlle…
CVE-2021-21409 medium 5.5 5y ago Possible request smuggling in HTTP/2 due missing validation of content-length
CVE-2021-25291 medium 5.5 5y ago An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.
CVE-2021-25292 medium 5.5 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-25290 medium 5.5 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-25293 medium 5.5 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-25289 medium 5.5 5y ago An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NO…
CVE-2021-27291 medium 5.5 5y ago RHSA-2021:4151: python27:2.7 security update (Moderate)
CVE-2021-28834 medium 5.5 5y ago Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
CVE-2021-28957 medium 5.5 5y ago RHSA-2021:4162: python38:3.8 and python38-devel:3.8 security update (Moderate)
CVE-2021-27290 medium 5.5 5y ago RHSA-2021:3074: nodejs:14 security, bug fix, and enhancement update (Moderate)
CVE-2021-27922 medium 5.5 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-27921 medium 5.5 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-27923 medium 5.5 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-21295 medium 5.5 5y ago Possible request smuggling in HTTP/2 due missing validation
CVE-2021-28305 medium 5.5 5y ago An issue was discovered in the diesel crate before 1.4.6 for Rust. There is a use-after-free in the SQLite backend because the semantics of sqlite3_column_name are not followed.
CVE-2021-21306 medium 5.5 5y ago Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. Thi…
CVE-2021-21290 medium 5.5 5y ago Local Information Disclosure Vulnerability in Netty on Unix-Like systems
CVE-2021-21240 medium 5.5 5y ago httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which responds with long series of "\xa0" characters in the "www-authenticate" header…
CVE-2021-3715 medium 5.5 6y ago A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free …
CVE-2021-2007 medium 5.5 6y ago RHSA-2020:5503: mariadb-connector-c security, bug fix, and enhancement update (Moderate)
CVE-2021-47981 medium 5.4 5.4 21d ago Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription par…
CVE-2021-47955 medium 5.4 5.4 21d ago CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicious SVG files through the file upload functionality…
CVE-2021-47948 medium 5.4 5.4 27d ago WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject arbitrary HTML code by exploiting the Help Text field in payment forms. Attackers…
CVE-2021-47870 medium 5.4 5.4 5mo ago GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin attempts to sanitize user input using htmlspecialchars(), but this can be bypasse…
CVE-2021-47817 medium 5.4 5.4 5mo ago OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers can chain with a file upload to achieve remote code execution. Attackers can expl…
CVE-2021-45479 medium 5.4 5.4 3y ago Improper Neutralization of Input During Web Page Generation vulnerability in Yordam Information Technologies Library Automation System allows Stored XSS. This issue affects Library Automation System…
CVE-2021-47934 medium 5.3 5.3 21d ago MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and …
CVE-2021-47946 medium 5.3 5.3 27d ago OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthenticated attackers to modify victim account details by tricking users into visiti…
CVE-2021-45475 medium 5.3 5.3 4y ago Yordam Library Information Document Automation product before version 19.02 has an unauthenticated Information disclosure vulnerability.
CVE-2021-44795 medium 5.3 5.3 4y ago Single Connect does not perform an authorization check when using the "sc-assigned-credential-ui" module. A remote attacker could exploit this vulnerability to modify users permissions. The exploitat…
CVE-2021-44794 medium 5.3 5.3 4y ago Single Connect does not perform an authorization check when using the "sc-diagnostic-ui" module. A remote attacker could exploit this vulnerability to access the device information page. The exploita…
CVE-2021-44792 medium 5.3 5.3 4y ago Single Connect does not perform an authorization check when using the "log-monitor" module. A remote attacker could exploit this vulnerability to access the logging interface. The exploitation of thi…
CVE-2021-35556 medium 5.3 5.3 5y ago RHSA-2022:0345: java-1.8.0-ibm security update (Important)
CVE-2021-3806 medium 5.3 5.3 5y ago A path traversal vulnerability on Pardus Software Center's "extractArchive" function could allow anyone on the same network to do a man-in-the-middle and write files on the system.
CVE-2021-22764 medium 5.3 5.3 5y ago A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could…
CVE-2021-22897 medium 5.3 5.3 5y ago curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The s…
CVE-2021-31944 medium 5.0 5.0 5y ago 3D Viewer Information Disclosure Vulnerability
CVE-2021-36647 medium 4.7 4.7 3y ago Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to pr…
CVE-2021-45476 medium 4.7 4.7 4y ago Yordam Library Information Document Automation product before version 19.02 has an unauthenticated reflected XSS vulnerability.
CVE-2021-22701 medium 4.5 4.5 5y ago A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that c…
CVE-2021-47958 medium 4.3 4.3 22d ago CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG file…
CVE-2021-47953 medium 4.3 4.3 27d ago OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick a…
CVE-2021-4479 medium 4.0 4.0 4d ago Dräger Atlan A350 software versions 1.00 through 1.01 contains an improper input handling vulnerability that allows attackers to cause a denial of service by sending specifically crafted non-Medibus-…
CVE-2021-46678 medium 4.0 4.0 4y ago A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the service name field.
CVE-2021-46680 medium 4.0 4.0 4y ago A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the module form name field.
CVE-2021-46677 medium 4.0 4.0 4y ago A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the event filter name field.
CVE-2021-46676 medium 4.0 4.0 4y ago A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the transactional maps name field.
CVE-2021-46679 medium 4.0 4.0 4y ago A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via service elements.
CVE-2021-46681 medium 4.0 4.0 4y ago A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via module massive operation name field.
CVE-2021-26086 unknown 2.5 2y ago Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.
CVE-2021-44529 unknown 2.5 2y ago Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
CVE-2021-27877 unknown 2.5 3y ago Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.
CVE-2021-27876 unknown 2.5 3y ago Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Ag…
CVE-2021-27878 unknown 2.5 3y ago Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.
CVE-2021-35587 unknown 2.5 4y ago Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.
CVE-2021-3493 unknown 2.5 4y ago The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.
CVE-2021-31166 unknown 2.5 4y ago Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
CVE-2021-21551 unknown 2.5 4y ago Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
CVE-2021-26085 unknown 2.5 4y ago Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
CVE-2021-42237 unknown 2.5 4y ago Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
CVE-2021-36934 unknown 2.5 4y ago If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.
CVE-2021-25296 unknown 2.5 4y ago Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-25297 unknown 2.5 4y ago Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-21975 unknown 2.5 4y ago Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to s…
CVE-2021-25298 unknown 2.5 4y ago Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-36260 unknown 2.5 5y ago A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
CVE-2021-45046 unknown 2.5 5y ago Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in…
CVE-2021-44077 unknown 2.5 5y ago Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution
CVE-2021-42321 unknown 2.5 5y ago An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
CVE-2021-40449 unknown 2.5 5y ago Unspecified vulnerability allows for an authenticated user to escalate privileges.
CVE-2021-38648 unknown 2.5 5y ago Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
CVE-2021-40539 unknown 2.5 5y ago Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
CVE-2021-35464 unknown 2.5 5y ago ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFram…
CVE-2021-38647 unknown 2.5 5y ago Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.
CVE-2021-22986 unknown 2.5 5y ago F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system co…
CVE-2021-22005 unknown 2.5 5y ago VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.
CVE-2021-1732 unknown 2.5 5y ago Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-34473 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-34527 unknown 2.5 5y ago Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an atta…
CVE-2021-27065 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2021-1675 unknown 2.5 5y ago Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-31207 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
CVE-2021-22502 unknown 2.5 5y ago Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-21985 unknown 2.5 5y ago VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code executio…
CVE-2021-34523 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-36942 unknown 2.5 5y ago Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to au…
CVE-2021-40444 unknown 2.5 5y ago Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
CVE-2021-30657 unknown 2.5 5y ago Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks.
CVE-2021-26855 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.