CVEs from 2021

4,783 normalized CVEs published or assigned in this year.

Total
4,783
critical
critical 281
high
high 1,014
medium
medium 1,186
low
low 139
% Critical
5.9%
% with KEV
4.5%
% with exploit
5.4%

Top products

  • simatic_wincc_runtime_advanced 28
  • office 13
  • primavera_gateway 10
  • weblogic_server 9
  • primavera_unifier 8
  • modicon_m340_bmxp342020 8
  • log4j 8
  • mbed_tls 8
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-28421 medium 5.5 arbitrary code execution in fluidsynth
CVE-2021-29944 medium 5.5 Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible. *Note: This issue o…
CVE-2021-30145 medium 5.5 A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file.
CVE-2021-30153 medium 5.5 An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an exi…
CVE-2021-30154 medium 5.5 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XS…
CVE-2021-30020 medium 5.5 In the function gf_hevc_read_pps_bs_internal function in media_tools/av_parsers.c in GPAC 1.0.1 there is a loop, which with crafted file, pps->num_tile_columns may be larger than sizeof(pps->column_w…
CVE-2021-31260 medium 5.5 The MergeTrack function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
CVE-2021-32269 medium 5.5 An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function ilst_item_box_dump located in box_dump.c. It allows an attacker to cause Denial of Service.
CVE-2021-36370 medium 5.5 An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the…
CVE-2021-38380 medium 5.5 multiple issues in live-media
CVE-2021-22238 medium 5.5 multiple issues in gitlab
CVE-2021-39282 medium 5.5 multiple issues in live-media
CVE-2021-32833 medium 5.5 arbitrary filesystem access in emby-server
CVE-2021-22257 medium 5.5 multiple issues in gitlab
CVE-2021-39283 medium 5.5 multiple issues in live-media
CVE-2021-32270 medium 5.5 An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function vwid_box_del located in box_code_base.c. It allows an attacker to cause Denial of Service.
CVE-2021-38381 medium 5.5 multiple issues in live-media
CVE-2021-22564 medium 5.5 For certain valid JPEG XL images with a size slightly larger than an integer number of groups (256x256 pixels) when processing the groups out of order the decoder can perform an out of bounds copy of…
CVE-2021-34529 medium 5.5 arbitrary code execution in code
CVE-2021-34477 medium 5.5 privilege escalation in code
CVE-2021-40516 medium 5.5 WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in plugins/relay/relay-websocket.c in the Relay plug…
CVE-2021-26437 medium 5.5 multiple issues in code
CVE-2021-3496 medium 5.5 A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.
CVE-2021-34479 medium 5.5 multiple issues in code
CVE-2021-41801 medium 5.5 The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (…
CVE-2021-42694 medium 5.5 content spoofing in rust
CVE-2021-35057 medium 5.5 multiple issues in hyperkitty
CVE-2021-39916 medium 5.5 multiple issues in gitlab
CVE-2021-39918 medium 5.5 multiple issues in gitlab
CVE-2021-39947 medium 5.5 multiple issues in gitlab-runner
CVE-2021-3935 medium 5.5 When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate ver…
CVE-2021-43814 medium 5.5 multiple issues in rizin
CVE-2021-4022 medium 5.5 multiple issues in rizin
CVE-2021-39939 medium 5.5 multiple issues in gitlab-runner
CVE-2021-22568 medium 5.5 multiple issues in dart
CVE-2021-37861 medium 5.5 information disclosure in mattermost
CVE-2021-44974 medium 5.5 radareorg radare2 version 5.5.2 is vulnerable to NULL Pointer Dereference via libr/bin/p/bin_symbols.c binary symbol parser.
CVE-2021-29450 medium 5.5 Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. Th…
CVE-2021-39200 medium 5.5 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under…
CVE-2021-41055 medium 5.5 Gajim 1.2.x and 1.3.x before 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted XMPP Last Message Correction (XEP-0308) message in multi-user chat, where the message ID …
CVE-2021-3403 medium 5.5 In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a …
CVE-2021-3404 medium 5.5 In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a c…
CVE-2021-30498 medium 5.5 A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption and other potential consequences.
CVE-2021-30499 medium 5.5 A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential consequences.
CVE-2021-3410 medium 5.5 A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context.
CVE-2021-27229 medium 5.5 Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.
CVE-2021-3648 medium 5.5 multiple issues in binutils
CVE-2021-1094 medium 5.5 multiple issues in nvidia-utils
CVE-2021-37600 medium 5.5 An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/se…
CVE-2021-3119 medium 5.5 Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to perform a remote denia…
CVE-2021-1077 medium 5.5 NVIDIA GPU Display Driver for Windows and Linux, R450 and R460 driver branch, contains a vulnerability where the software uses a reference count to manage a resource that is incorrectly updated, whic…
CVE-2021-22117 medium 5.5 RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.
CVE-2021-34555 medium 5.5 OpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a multi-value From header field.
CVE-2021-33365 medium 5.5 Memory leak in the gf_isom_get_root_od function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
CVE-2021-26933 medium 5.5 An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether memory accesses are bypassing the cache. This means that Xen needs to ensure that all writes (such as …
CVE-2021-37156 medium 5.5 Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.
CVE-2021-47670 medium 5.5 10mo ago In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_…
CVE-2021-43612 medium 5.5 2y ago Moderate: lldpd security update
CVE-2021-47505 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: aio: fix use-after-free due to missing POLLFREE handling signalfd_poll() and binder_poll() are special in that they use a waitque…
CVE-2021-47098 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Prevent integer overflow/underflow in hysteresis calculations Commit b50aa49638c7 ("hwmon: (lm90) Prevent integer u…
CVE-2021-47185 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc When running ltp testcase(ltp/testcases/kernel/pty/pty04.c) with arm6…
CVE-2021-47428 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: powerpc/64s: fix program check interrupt emergency stack path Emergency stack path was jumping into a 3: label inside the __GEN_C…
CVE-2021-47454 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: powerpc/smp: do not decrement idle task preempt count in CPU offline With PREEMPT_COUNT=y, when a CPU is offlined and then online…
CVE-2021-47457 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: can: isotp: isotp_sendmsg(): add result check for wait_event_interruptible() Using wait_event_interruptible() to wait for complet…
CVE-2021-47429 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: powerpc/64s: Fix unrecoverable MCE calling async handler from NMI The machine check handler is not considered NMI on 64s. The ear…
CVE-2021-47383 medium 5.5 2y ago Moderate: kernel security update
CVE-2021-47385 medium 5.5 2y ago Moderate: kernel security update
CVE-2021-47459 medium 5.5 2y ago Moderate: kernel security update
CVE-2021-47400 medium 5.5 2y ago Moderate: kernel security and bug fix update
CVE-2021-41092 medium 5.5 2y ago Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-registry.example.com` with a misconfigured configur…
CVE-2021-41089 medium 5.5 2y ago Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted…
CVE-2021-47055 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: mtd: require write permissions for locking and badblock ioctls MEMLOCK, MEMUNLOCK and OTPLOCK modify protection bits. Thus requir…
CVE-2021-47013 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send In emac_mac_tx_buf_send, it calls emac_tx_fill_tpd(..,skb,..). If…
CVE-2021-47118 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: pid: take a reference when initializing `cad_pid` During boot, kernel_init_freeable() initializes `cad_pid` to the init task's st…
CVE-2021-47153 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: i2c: i801: Don't generate an interrupt on bus reset Now that the i2c-i801 driver supports interrupts, setting the KILL bit in a a…
CVE-2021-46934 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: i2c: validate user data in compat ioctl Wrong user data may cause warning in i2c_transfer(), ex: zero msgs. Userspace should not …
CVE-2021-47171 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: net: usb: fix memory leak in smsc75xx_bind Syzbot reported memory leak in smsc75xx_bind(). The problem was is non-freed memory in…
CVE-2021-4204 medium 5.5 2y ago An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or l…
CVE-2021-3753 medium 5.5 2y ago A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_i…
CVE-2021-47316 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: nfsd: fix NULL dereference in nfs3svc_encode_getaclres In error cases the dentry may be NULL. Before 20798dfe249a, the encoder a…
CVE-2021-41244 medium 5.5 2y ago access restriction bypass in grafana
CVE-2021-29390 medium 5.5 2y ago Moderate: libjpeg-turbo security update
CVE-2021-41072 medium 5.5 2y ago Moderate: squashfs-tools security update
CVE-2021-40153 medium 5.5 2y ago Moderate: squashfs-tools security update
CVE-2021-41043 medium 5.5 2y ago RHSA-2024:0769: tcpdump security update (Moderate)
CVE-2021-3382 medium 5.5 2y ago Buffer Overflow in gitea in code.gitea.io/gitea
CVE-2021-47188 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Improve SCSI abort handling The following has been observed on a test setup: WARNING: CPU: 4 PID: 250 at driver…
CVE-2021-47002 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix null pointer dereference in svc_rqst_free() When alloc_pages_node() returns null in svc_rqst_alloc(), the null rq_scr…
CVE-2021-41091 medium 5.5 2y ago Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirec…
CVE-2021-21334 medium 5.5 2y ago containerd environment variable leak
CVE-2021-3282 medium 5.5 2y ago Improper Authentication in HashiCorp Vault in github.com/hashicorp/vault
CVE-2021-21285 medium 5.5 2y ago In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain…
CVE-2021-21284 medium 5.5 2y ago In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns…
CVE-2021-35938 medium 5.5 2y ago Moderate: rpm security update
CVE-2021-35939 medium 5.5 2y ago Moderate: rpm security update
CVE-2021-35937 medium 5.5 2y ago Moderate: rpm security update
CVE-2021-32142 medium 5.5 3y ago RHSA-2024:2994: LibRaw security update (Moderate)
CVE-2021-43784 medium 5.5 3y ago Moderate: runc security update
CVE-2021-3502 medium 5.5 3y ago Moderate: avahi security update
CVE-2021-3468 medium 5.5 3y ago Moderate: avahi security update