CVEs from 2021
Total
4,786
critical
critical 281
high
high 1,022
medium
medium 1,179
low
low 138
% Critical
5.9%
% with KEV
4.5%
% with exploit
5.3%
Top vendors
Top products
- simatic_wincc_runtime_advanced 28
- office 13
- primavera_gateway 10
- weblogic_server 9
- primavera_unifier 8
- modicon_m340_bmxp342020 8
- log4j 8
- mbed_tls 8
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-47587 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: systemport: Add global locking for descriptor lifecycle The descriptor list is a shared resource across all of the transmit … | |||
| CVE-2021-47589 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: igbvf: fix double free in `igbvf_probe` In `igbvf_probe`, if register_netdev() fails, the program will go to label err_hw_init, a… | |||
| CVE-2021-47595 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_ets: don't remove idle classes from the round-robin list Shuang reported that the following script: 1) tc qdisc … | |||
| CVE-2021-47599 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: btrfs: use latest_dev in btrfs_show_devname The test case btrfs/238 reports the warning below: WARNING: CPU: 3 PID: 481 at fs/b… | |||
| CVE-2021-47600 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: dm btree remove: fix use after free in rebalance_children() Move dm_tm_unlock() after dm_tm_dec(). | |||
| CVE-2021-47601 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: tee: amdtee: fix an IS_ERR() vs NULL bug The __get_free_pages() function does not return error pointers it returns NULL so fix th… | |||
| CVE-2021-47603 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: audit: improve robustness of the audit queue handling If the audit daemon were ever to get stuck in a stopped state the kernel's … | |||
| CVE-2021-47610 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix null ptr access msm_ioctl_gem_submit() Fix the below null pointer dereference in msm_ioctl_gem_submit(): 26545.260… | |||
| CVE-2021-47604 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vduse: check that offset is within bounds in get_config() This condition checks "len" but it does not check "offset" and that cou… | |||
| CVE-2021-47605 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vduse: fix memory corruption in vduse_dev_ioctl() The "config.offset" comes from the user. There needs to a check to prevent it … | |||
| CVE-2021-47607 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix kernel address leakage in atomic cmpxchg's r0 aux reg The implementation of BPF_CMPXCHG on a high level has the followin… | |||
| CVE-2021-47608 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix kernel address leakage in atomic fetch The change in commit 37086bfdc737 ("bpf: Propagate stack bounds to registers in a… | |||
| CVE-2021-47613 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: i2c: virtio: fix completion handling The driver currently assumes that the notify callback is only received when the device is do… | |||
| CVE-2021-47655 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: media: venus: vdec: fixed possible memory leak issue The venus_helper_alloc_dpb_bufs() implementation allows an early return on a… | |||
| CVE-2021-47652 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: video: fbdev: smscufx: Fix null-ptr-deref in ufx_usb_probe() I got a null-ptr-deref report: BUG: kernel NULL pointer dereference… | |||
| CVE-2021-47653 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: media: davinci: vpif: fix use-after-free on driver unbind The driver allocates and registers two platform device structures durin… | |||
| CVE-2021-47654 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: samples/landlock: Fix path_list memory leak Clang static analysis reports this error sandboxer.c:134:8: warning: Potential leak … | |||
| CVE-2021-47656 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: jffs2: fix use-after-free in jffs2_clear_xattr_subsystem When we mount a jffs2 image, assume that the first few blocks of the ima… | |||
| CVE-2021-47658 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix a potential gpu_metrics_table memory leak Memory is allocated for gpu_metrics_table in renoir_init_smc_tables(), … | |||
| CVE-2021-47659 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/plane: Move range check for format_count earlier While the check for format_count > 64 in __drm_universal_plane_init() should… | |||
| CVE-2021-47660 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix some memory leaks in an error handling path of 'log_replay()' All error handling paths lead to 'out' where many res… | |||
| CVE-2021-23520 | unknown | — | — | — | The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability… | |||
| CVE-2021-47668 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: can: dev: can_restart: fix use after free bug After calling netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_fr… | |||
| CVE-2021-46747 | unknown | — | — | 5d ago | Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System Management Network) apertures lead… | |||
| CVE-2021-47621 | unknown | — | — | 2y ago | ClassGraph XML External Entity Reference | |||
| CVE-2021-3754 | unknown | — | — | 2y ago | Keycloak's improper input validation allows using email as username | |||
| CVE-2021-22573 | unknown | — | — | 2y ago | google-oauth-java-client improperly verifies cryptographic signature | |||
| CVE-2021-28656 | unknown | — | — | 2y ago | Apache Zeppelin CSRF vulnerability in the Credentials page | |||
| CVE-2021-29050 | unknown | — | — | 2y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery in Terms of Use Page | |||
| CVE-2021-29038 | unknown | — | — | 2y ago | Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers | |||
| CVE-2021-37942 | unknown | — | — | 3y ago | APM Java Agent Local Privilege Escalation issue | |||
| CVE-2021-32050 | unknown | — | — | 3y ago | Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data… | |||
| CVE-2021-28655 | unknown | — | — | 3y ago | Apache Zeppelin Improper Input Validation vulnerability | |||
| CVE-2021-31635 | unknown | — | — | 3y ago | jFinal Server-Side Template Injection vulnerability | |||
| CVE-2021-40331 | unknown | — | — | 3y ago | Apache Ranger Hive Plugin missing permissions check | |||
| CVE-2021-28235 | unknown | — | — | 3y ago | Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function. | |||
| CVE-2021-46877 | unknown | — | — | 3y ago | jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonN… | |||
| CVE-2021-37305 | unknown | — | — | 3y ago | Insecure Permissions issue in jeecg-boot | |||
| CVE-2021-37304 | unknown | — | — | 3y ago | Insecure Permissions issue in jeecg-boot | |||
| CVE-2021-37306 | unknown | — | — | 3y ago | Insecure Permissions issue in jeecg-boot | |||
| CVE-2021-32828 | unknown | — | — | 4y ago | Nuxeo vulnerable to Reflected Cross-Site Scripting leading to Remote Code Execution | |||
| CVE-2021-32824 | unknown | — | — | 4y ago | Apache Dubbo vulnerable to remote code execution via Telnet Handler | |||
| CVE-2021-37533 | unknown | — | — | 4y ago | Apache Commons Net vulnerable to information leakage via malicious server | |||
| CVE-2021-42010 | unknown | — | — | 4y ago | Heron allows CRLF log injection | |||
| CVE-2021-43980 | unknown | — | — | 4y ago | The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in … | |||
| CVE-2021-43565 | unknown | — | — | 4y ago | The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server. | |||
| CVE-2021-3856 | unknown | — | — | 4y ago | Keycloak has Files or Directories Accessible to External Parties | |||
| CVE-2021-3644 | unknown | — | — | 4y ago | wildfly-core allows user with access to management interface to access vault expression, retrieve item from vault | |||
| CVE-2021-25642 | unknown | — | — | 4y ago | Deserialization of Untrusted Data in Apache Hadoop YARN | |||
| CVE-2021-42521 | unknown | — | — | 4y ago | There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', … | |||
| CVE-2021-3914 | unknown | — | — | 4y ago | SmallRye Health UI Cross-site Scripting vulnerability | |||
| CVE-2021-4040 | unknown | — | — | 4y ago | org.apache.activemq:artemis-core-client Vulnerable to Out-of-Bounds Write | |||
| CVE-2021-34538 | unknown | — | — | 4y ago | Apache Hive before 3.1.3 `CREATE` and `DROP` function operations do not check for necessary authorization. | |||
| CVE-2021-3859 | unknown | — | — | 4y ago | Undertow vulnerable to Denial of Service (DoS) attacks | |||
| CVE-2021-3690 | unknown | — | — | 4y ago | Undertow vulnerable to memory exhaustion due to buffer leak | |||
| CVE-2021-4178 | unknown | — | — | 4y ago | fabric8 kubernetes-client vulnerable | |||
| CVE-2021-44791 | unknown | — | — | 4y ago | Apache Druid before 0.23.0 vulnerable to reflected XSS via unescaped URL parameters | |||
| CVE-2021-41042 | unknown | — | — | 4y ago | XML External Entity Reference in Eclipse Lyo | |||
| CVE-2021-41411 | unknown | — | — | 4y ago | XML External Entity Reference in drools | |||
| CVE-2021-33036 | unknown | — | — | 4y ago | User account escalation in Apache Hadoop | |||
| CVE-2021-40660 | unknown | — | — | 4y ago | Regular expression denial of service in Delight Nashorn Sandbox | |||
| CVE-2021-37404 | unknown | — | — | 4y ago | Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2 | |||
| CVE-2021-3717 | unknown | — | — | 4y ago | Wildfly-Core user account mismanagement | |||
| CVE-2021-3629 | unknown | — | — | 4y ago | Undertow Uncontrolled Resource Consumption | |||
| CVE-2021-3597 | unknown | — | — | 4y ago | undertow Race Condition vulnerability | |||
| CVE-2021-33322 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP fails to invalidate password reset tokens after use | |||
| CVE-2021-20328 | unknown | — | — | 4y ago | Improper Certificate Validation in MongoDB | |||
| CVE-2021-33330 | unknown | — | — | 4y ago | Exposure of Resource to Wrong Sphere in Liferay Portal | |||
| CVE-2021-29049 | unknown | — | — | 4y ago | Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the currentURL Parameter | |||
| CVE-2021-21662 | unknown | — | — | 4y ago | Missing permission check in Jenkins XebiaLabs XL Deploy Plugin allows enumerating credentials IDs | |||
| CVE-2021-43576 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins pom2config Plugin | |||
| CVE-2021-21700 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins Scriptler Plugin | |||
| CVE-2021-21699 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins Active Choices Plugin | |||
| CVE-2021-43577 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins OWASP Dependency-Check Plugin | |||
| CVE-2021-21701 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins Performance Plugin | |||
| CVE-2021-43578 | unknown | — | — | 4y ago | Agent-to-controller security bypass in Jenkins Squash TM Publisher (Squash4Jenkins) Plugin allows writing arbitrary files | |||
| CVE-2021-21698 | unknown | — | — | 4y ago | Path traversal vulnerability in Jenkins Subversion Plugin allows reading arbitrary files | |||
| CVE-2021-22096 | unknown | — | — | 4y ago | Improper Output Neutralization for Logs in Spring Framework | |||
| CVE-2021-22044 | unknown | — | — | 4y ago | Exposure of Resource to Wrong Sphere in Spring Cloud OpenFeign | |||
| CVE-2021-22097 | unknown | — | — | 4y ago | Deserialization of Untrusted Data in Spring AMQP | |||
| CVE-2021-22047 | unknown | — | — | 4y ago | Exposure of Resource to Wrong Sphere in Spring Data REST | |||
| CVE-2021-2471 | unknown | — | — | 4y ago | Incorrect Authorization in MySQL Connector Java | |||
| CVE-2021-3869 | unknown | — | — | 4y ago | Improper Restriction of XML External Entity Reference in Stanford CoreNLP | |||
| CVE-2021-3878 | unknown | — | — | 4y ago | Improper Restriction of XML External Entity Reference in Stanford CoreNLP | |||
| CVE-2021-21684 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins Git Plugin | |||
| CVE-2021-40824 | unknown | — | — | 4y ago | Logic error in Matrix SDK for Android | |||
| CVE-2021-40797 | unknown | — | — | 4y ago | An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authentic… | |||
| CVE-2021-21678 | unknown | — | — | 4y ago | Jenkins SAML Plugin allows bypassing CSRF protection for any URL | |||
| CVE-2021-21680 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins Nested View Plugin | |||
| CVE-2021-21677 | unknown | — | — | 4y ago | RCE vulnerability in Jenkins Code Coverage API Plugin | |||
| CVE-2021-21679 | unknown | — | — | 4y ago | Jenkins Azure AD Plugin allows bypassing CSRF protection for any URL | |||
| CVE-2021-21681 | unknown | — | — | 4y ago | Password stored in plain text by Jenkins Nomad Plugin | |||
| CVE-2021-40085 | unknown | — | — | 4y ago | An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value. | |||
| CVE-2021-38598 | unknown | — | — | 4y ago | OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending c… | |||
| CVE-2021-28490 | unknown | — | — | 4y ago | Cross-Site Request Forgery in OWASP CSRFGuard | |||
| CVE-2021-38155 | unknown | — | — | 4y ago | OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). … | |||
| CVE-2021-33335 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers | |||
| CVE-2021-3642 | unknown | — | — | 4y ago | Observable Discrepancy in Wildfly Elytron | |||
| CVE-2021-33338 | unknown | — | — | 4y ago | Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs | |||
| CVE-2021-33339 | unknown | — | — | 4y ago | Liferay Portal Fragment Module and Liferay DXP Vulnerable to Cross-Site Scripting |