CVEs from 2021

5,048 normalized CVEs published or assigned in this year.

Total
5,048
critical
critical 273
high
high 975
medium
medium 1,141
low
low 135
% Critical
5.4%
% with KEV
4.2%
% with exploit
4.2%

Top products

  • office 13
  • 365_apps 6
  • office_long_term_servicing_channel 6
  • library_automation_system 5
  • single_connect 4
  • http_server 3
  • solidfire 2
  • student_information_management_system 2
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2021-3156 critical 10.0 4y ago Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation. archsusedebian
CVE-2021-4102 critical 10.0 5y ago Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl… archdebian
CVE-2021-44228 critical 10.0 5y ago Remote code injection in Log4j archdebiansusejava
CVE-2021-30551 critical 10.0 5y ago multiple issues in chromium archdebiansuse
CVE-2021-42013 critical 10.0 5y ago Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under defa… archdebian
CVE-2021-21148 critical 10.0 5y ago multiple issues in chromium archdebiansuse
CVE-2021-22205 critical 10.0 5y ago GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through Exi… arch
CVE-2021-39935 high 9.5 4mo ago GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API. arch
CVE-2021-22555 high 9.5 8mo ago A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through… archsuserockylinuxdebian
CVE-2021-43798 high 9.5 2y ago Grafana contains a path traversal vulnerability that could allow access to local files. archsusegolang
CVE-2021-3560 high 9.5 3y ago Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation. archsuserockylinuxdebian
CVE-2021-30533 high 9.5 4y ago multiple issues in chromium archdebian
CVE-2021-4034 high 9.5 4y ago Important: polkit security update archsuserockylinuxdebian
CVE-2021-0920 high 9.5 4y ago In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interac… suserockylinuxdebian
CVE-2021-40438 high 9.5 5y ago Important: httpd:2.4 security update debianarchsuserockylinux
CVE-2021-30563 high 9.5 5y ago arbitrary code execution in chromium archdebian
CVE-2021-38003 high 9.5 5y ago multiple issues in chromium archdebian
CVE-2021-30632 high 9.5 5y ago arbitrary code execution in chromium archdebian
CVE-2021-38000 high 9.5 5y ago multiple issues in chromium archdebian
CVE-2021-30633 high 9.5 5y ago arbitrary code execution in chromium archdebian
CVE-2021-30554 high 9.5 5y ago arbitrary code execution in chromium archdebian
CVE-2021-21224 high 9.5 5y ago multiple issues in chromium archdebian
CVE-2021-21193 high 9.5 5y ago arbitrary code execution in chromium archdebian
CVE-2021-37975 high 9.5 5y ago Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl… archdebian
CVE-2021-37976 high 9.5 5y ago Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a c… archdebian
CVE-2021-41773 high 9.5 5y ago Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under defa… debianarchsuse
CVE-2021-21206 high 9.5 5y ago Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple we… archdebian
CVE-2021-21220 high 9.5 5y ago Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could af… archdebian
CVE-2021-21166 high 9.5 5y ago Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web brow… archdebian
CVE-2021-37973 high 9.5 5y ago Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML pag… archdebian
CVE-2021-39226 high 9.5 5y ago Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss. archsuserockylinuxgolang
CVE-2021-30952 medium 7.0 3mo ago Moderate: webkit2gtk3 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2021-1789 medium 7.0 4y ago Moderate: GNOME security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2021-22204 medium 7.0 5y ago Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image archdebian
CVE-2021-30663 medium 7.0 5y ago Moderate: GNOME security, bug fix, and enhancement update archrockylinuxdebian
CVE-2021-1871 medium 7.0 5y ago Moderate: GNOME security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2021-30761 medium 7.0 5y ago Moderate: GNOME security, bug fix, and enhancement update archrockylinuxdebianalmalinux
CVE-2021-30665 medium 7.0 5y ago Moderate: GNOME security, bug fix, and enhancement update archrockylinuxdebianalmalinux
CVE-2021-30666 medium 7.0 5y ago Moderate: GNOME security, bug fix, and enhancement update archrockylinuxdebianalmalinux
CVE-2021-30762 medium 7.0 5y ago Moderate: GNOME security, bug fix, and enhancement update archrockylinuxdebianalmalinux
CVE-2021-30858 medium 7.0 5y ago Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers t… archsuserockylinuxdebian
CVE-2021-1870 medium 7.0 5y ago Moderate: GNOME security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2021-30661 medium 7.0 5y ago Moderate: GNOME security, bug fix, and enhancement update archrockylinuxdebian
CVE-2021-44026 unknown 1.5 3y ago Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. debian
CVE-2021-3493 unknown 1.5 4y ago The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combinati… susedebian
CVE-2021-1048 unknown 1.5 4y ago In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges neede… susedebian
CVE-2021-22600 unknown 1.5 4y ago A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past t… susedebian
CVE-2021-45046 unknown 1.5 5y ago Incomplete fix for Apache Log4j vulnerability debiansusejava
CVE-2021-39144 unknown 1.5 5y ago XStream is vulnerable to a Remote Command Execution attack susedebianjava