CVEs from 2021
Total
4,783
critical
critical 281
high
high 1,014
medium
medium 1,186
low
low 139
% Critical
5.9%
% with KEV
4.5%
% with exploit
5.4%
Top vendors
Top products
- simatic_wincc_runtime_advanced 28
- office 13
- primavera_gateway 10
- weblogic_server 9
- primavera_unifier 8
- modicon_m340_bmxp342020 8
- log4j 8
- mbed_tls 8
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-3671 | low | — | 2.5 | — | A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samb… | |||
| CVE-2021-3478 | low | — | 2.5 | — | There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory… | |||
| CVE-2021-20216 | low | — | 2.5 | — | A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is t… | |||
| CVE-2021-3476 | low | — | 2.5 | — | A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially aff… | |||
| CVE-2021-3927 | low | — | 2.5 | — | vim is vulnerable to Heap-based Buffer Overflow | |||
| CVE-2021-3875 | low | — | 2.5 | — | vim is vulnerable to Heap-based Buffer Overflow | |||
| CVE-2021-3928 | low | — | 2.5 | — | vim is vulnerable to Use of Uninitialized Variable | |||
| CVE-2021-3973 | low | — | 2.5 | — | vim is vulnerable to Heap-based Buffer Overflow | |||
| CVE-2021-3178 | low | — | 2.5 | — | fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPL… | |||
| CVE-2021-30046 | low | — | 2.5 | — | denial of service in vigra | |||
| CVE-2021-4069 | low | — | 2.5 | — | vim is vulnerable to Use After Free | |||
| CVE-2021-32613 | low | — | 2.5 | — | In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS. | |||
| CVE-2021-30218 | low | — | 2.5 | — | denial of service in samurai | |||
| CVE-2021-32275 | low | — | 2.5 | — | An issue was discovered in faust through v2.30.5. A NULL pointer dereference exists in the function CosPrim::computeSigOutput() located in cosprim.hh. It allows an attacker to cause Denial of Service. | |||
| CVE-2021-1404 | low | — | 2.5 | — | A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an… | |||
| CVE-2021-22207 | low | — | 2.5 | — | Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-39924 | low | — | 2.5 | — | Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-39922 | low | — | 2.5 | — | Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-37621 | low | — | 2.5 | — | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infini… | |||
| CVE-2021-4023 | low | — | 2.5 | — | A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-urin… | |||
| CVE-2021-34183 | low | — | 2.5 | — | denial of service in imagemagick | |||
| CVE-2021-30219 | low | — | 2.5 | — | denial of service in samurai | |||
| CVE-2021-41865 | low | — | 2.5 | — | denial of service in nomad | |||
| CVE-2021-39929 | low | — | 2.5 | — | Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-22173 | low | — | 2.5 | — | Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-32718 | low | — | 2.5 | — | cross-site scripting in rabbitmq | |||
| CVE-2021-39247 | low | — | 2.5 | — | Zint Barcode Generator before 2.10.0 has a one-byte buffer over-read, related to is_last_single_ascii in code1.c, and rs_encode_uint in reedsol.c. | |||
| CVE-2021-39220 | low | — | 2.5 | — | information disclosure in nextcloud-app-mail | |||
| CVE-2021-27212 | low | — | 2.5 | — | In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemo… | |||
| CVE-2021-3974 | low | — | 2.5 | — | vim is vulnerable to Use After Free | |||
| CVE-2021-35331 | low | — | 2.5 | — | In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding | |||
| CVE-2021-37623 | low | — | 2.5 | — | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infini… | |||
| CVE-2021-32815 | low | — | 2.5 | — | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The assertion failure is triggered when Exiv2 is used to modify the metadata… | |||
| CVE-2021-20205 | low | — | 2.5 | — | Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image. | |||
| CVE-2021-1252 | low | — | 2.5 | — | A vulnerability in the Excel XLM macro parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service con… | |||
| CVE-2021-20177 | low | — | 2.5 | — | A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root or CAP_NET_ADMIN) when inserting iptables rules could insert a rule which can pa… | |||
| CVE-2021-28039 | low | — | 2.5 | — | An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of… | |||
| CVE-2021-27375 | low | — | 2.5 | — | insufficient validation in traefik | |||
| CVE-2021-3673 | low | — | 2.5 | — | A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and DoS. | |||
| CVE-2021-34813 | low | — | 2.5 | — | Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has … | |||
| CVE-2021-27815 | low | — | 2.5 | — | NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicio… | |||
| CVE-2021-3479 | low | — | 2.5 | — | There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger excessive consumption o… | |||
| CVE-2021-26934 | low | — | 2.5 | — | An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration… | |||
| CVE-2021-1405 | low | — | 2.5 | — | A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service con… | |||
| CVE-2021-33500 | low | — | 2.5 | — | PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its title repeatedly at high speed, which results in many SetW… | |||
| CVE-2021-36367 | low | — | 2.5 | — | PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a l… | |||
| CVE-2021-28089 | low | — | 2.5 | — | Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001. | |||
| CVE-2021-22235 | low | — | 2.5 | — | Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-37622 | low | — | 2.5 | — | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infini… | |||
| CVE-2021-20189 | low | — | 2.5 | — | incorrect calculation in imagemagick | |||
| CVE-2021-4110 | low | — | 2.5 | — | mruby is vulnerable to NULL Pointer Dereference | |||
| CVE-2021-40985 | low | — | 2.5 | — | A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp. | |||
| CVE-2021-22174 | low | — | 2.5 | — | Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-39928 | low | — | 2.5 | — | NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-28090 | low | — | 2.5 | — | Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002. | |||
| CVE-2021-37615 | low | — | 2.5 | — | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. … | |||
| CVE-2021-32719 | low | — | 2.5 | — | cross-site scripting in rabbitmq | |||
| CVE-2021-3443 | low | — | 2.5 | — | denial of service in jasper | |||
| CVE-2021-39925 | low | — | 2.5 | — | Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |||
| CVE-2021-3903 | low | — | 2.5 | 2y ago | vim is vulnerable to Heap-based Buffer Overflow | |||
| CVE-2021-26086 | unknown | — | 2.5 | 2y ago | Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint. | |||
| CVE-2021-44529 | unknown | — | 2.5 | 2y ago | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody). | |||
| CVE-2021-43618 | low | — | 2.5 | 3y ago | Low: gmp security and enhancement update | |||
| CVE-2021-3826 | low | — | 2.5 | 3y ago | Low: gdb security update | |||
| CVE-2021-27876 | unknown | — | 2.5 | 3y ago | Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Ag… | |||
| CVE-2021-27877 | unknown | — | 2.5 | 3y ago | Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme. | |||
| CVE-2021-27878 | unknown | — | 2.5 | 3y ago | Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine. | |||
| CVE-2021-35587 | unknown | — | 2.5 | 4y ago | Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product. | |||
| CVE-2021-46195 | low | — | 2.5 | 4y ago | Low: mingw-gcc security and bug fix update | |||
| CVE-2021-44269 | low | — | 2.5 | 4y ago | RHSA-2022:7558: wavpack security update (Low) | |||
| CVE-2021-3507 | low | — | 2.5 | 4y ago | A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers fr… | |||
| CVE-2021-3493 | unknown | — | 2.5 | 4y ago | The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation. | |||
| CVE-2021-3981 | low | — | 2.5 | 4y ago | RHSA-2022:2110: grub2 security, bug fix, and enhancement update (Low) | |||
| CVE-2021-3634 | low | — | 2.5 | 4y ago | RHSA-2022:2031: libssh security, bug fix, and enhancement update (Low) | |||
| CVE-2021-3802 | low | — | 2.5 | 4y ago | RHSA-2022:1820: udisks2 security and bug fix update (Low) | |||
| CVE-2021-41229 | low | — | 2.5 | 4y ago | RHSA-2022:2081: bluez security update (Low) | |||
| CVE-2021-23222 | low | — | 2.5 | 4y ago | man-in-the-middle in postgresql, postgresql-libs | |||
| CVE-2021-31166 | unknown | — | 2.5 | 4y ago | Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution. | |||
| CVE-2021-3461 | low | — | 2.5 | 4y ago | Keycloak insufficient session expiration | |||
| CVE-2021-21551 | unknown | — | 2.5 | 4y ago | Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure. | |||
| CVE-2021-26085 | unknown | — | 2.5 | 4y ago | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. | |||
| CVE-2021-42237 | unknown | — | 2.5 | 4y ago | Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution. | |||
| CVE-2021-4091 | low | — | 2.5 | 4y ago | RHSA-2022:0889: 389-ds:1.4 security and bug fix update (Low) | |||
| CVE-2021-36934 | unknown | — | 2.5 | 4y ago | If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level. | |||
| CVE-2021-21975 | unknown | — | 2.5 | 4y ago | Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to s… | |||
| CVE-2021-25297 | unknown | — | 2.5 | 4y ago | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | |||
| CVE-2021-25296 | unknown | — | 2.5 | 4y ago | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | |||
| CVE-2021-25298 | unknown | — | 2.5 | 4y ago | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | |||
| CVE-2021-36260 | unknown | — | 2.5 | 5y ago | A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation. | |||
| CVE-2021-20257 | low | — | 2.5 | 5y ago | An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized wi… | |||
| CVE-2021-3930 | low | — | 2.5 | 5y ago | An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). … | |||
| CVE-2021-45046 | unknown | — | 2.5 | 5y ago | Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in… | |||
| CVE-2021-44077 | unknown | — | 2.5 | 5y ago | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution | |||
| CVE-2021-43668 | low | — | 2.5 | 5y ago | Denial of Service in Go-Ethereum | |||
| CVE-2021-40449 | unknown | — | 2.5 | 5y ago | Unspecified vulnerability allows for an authenticated user to escalate privileges. | |||
| CVE-2021-42321 | unknown | — | 2.5 | 5y ago | An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution. | |||
| CVE-2021-3572 | low | — | 2.5 | 5y ago | A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest… | |||
| CVE-2021-20266 | low | — | 2.5 | 5y ago | RHSA-2021:4489: rpm security, bug fix, and enhancement update (Low) | |||
| CVE-2021-3200 | low | — | 2.5 | 5y ago | Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c… | |||
| CVE-2021-43566 | low | — | 2.5 | 5y ago | RHBA-2021:4438: samba bug fix and enhancement update (Low) |