CVEs from 2021

4,865 normalized CVEs published or assigned in this year.

Total
4,865
critical
critical 279
high
high 1,005
medium
medium 1,166
low
low 138
% Critical
5.7%
% with KEV
4.4%
% with exploit
5.3%

Top products

  • office 13
  • primavera_gateway 10
  • weblogic_server 9
  • modicon_m340_bmxp342020 8
  • log4j 8
  • primavera_unifier 8
  • retail_service_backbone 7
  • communications_unified_inventory_management 7
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-27905 medium 5.5 5y ago Server-Side Request Forgery in Apache Solr
CVE-2021-29943 medium 5.5 5y ago Incorrect Authorization in Apache Solr
CVE-2021-21419 medium 5.5 5y ago Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious peer may exhaust memory on Eventlet side…
CVE-2021-23362 medium 5.5 5y ago RHSA-2021:3074: nodejs:14 security, bug fix, and enhancement update (Moderate)
CVE-2021-22885 medium 5.5 5y ago A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
CVE-2021-22902 medium 5.5 5y ago The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of A…
CVE-2021-22904 medium 5.5 5y ago The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive …
CVE-2021-22903 medium 5.5 5y ago The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Author…
CVE-2021-31799 medium 5.5 5y ago RHSA-2022:0672: ruby:2.5 security update (Moderate)
CVE-2021-23841 medium 5.5 5y ago RHSA-2021:4424: openssl security and bug fix update (Moderate)
CVE-2021-23840 medium 5.5 5y ago RHSA-2021:4424: openssl security and bug fix update (Moderate)
CVE-2021-29472 medium 5.5 5y ago Composer's missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial
CVE-2021-29425 medium 5.5 5y ago Path Traversal and Improper Input Validation in Apache Commons IO
CVE-2021-20270 medium 5.5 5y ago RHSA-2021:4151: python27:2.7 security update (Moderate)
CVE-2021-29421 medium 5.5 5y ago models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
CVE-2021-2163 medium 5.5 5y ago RHSA-2022:6735: java-1.8.0-ibm security update (Moderate)
CVE-2021-3115 medium 5.5 5y ago RHSA-2021:1746: go-toolset:rhel8 security, bug fix, and enhancement update (Moderate)
CVE-2021-29949 medium 5.5 5y ago RHSA-2021:1193: thunderbird security update (Moderate)
CVE-2021-23991 medium 5.5 5y ago RHSA-2021:1193: thunderbird security update (Moderate)
CVE-2021-23992 medium 5.5 5y ago RHSA-2021:1193: thunderbird security update (Moderate)
CVE-2021-23993 medium 5.5 5y ago RHSA-2021:1193: thunderbird security update (Moderate)
CVE-2021-29950 medium 5.5 5y ago RHSA-2021:1193: thunderbird security update (Moderate)
CVE-2021-20295 medium 5.5 5y ago RHSA-2021:1064: virt:rhel and virt-devel:rhel security update (Moderate)
CVE-2021-28965 medium 5.5 5y ago RHSA-2021:2588: ruby:2.6 security, bug fix, and enhancement update (Moderate)
CVE-2021-3447 medium 5.5 5y ago A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controlle…
CVE-2021-21409 medium 5.5 5y ago Possible request smuggling in HTTP/2 due missing validation of content-length
CVE-2021-25291 medium 5.5 5y ago An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.
CVE-2021-25292 medium 5.5 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-25290 medium 5.5 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-25293 medium 5.5 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-25289 medium 5.5 5y ago An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NO…
CVE-2021-27291 medium 5.5 5y ago RHSA-2021:4151: python27:2.7 security update (Moderate)
CVE-2021-28834 medium 5.5 5y ago Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
CVE-2021-28957 medium 5.5 5y ago RHSA-2021:4162: python38:3.8 and python38-devel:3.8 security update (Moderate)
CVE-2021-27290 medium 5.5 5y ago RHSA-2021:3074: nodejs:14 security, bug fix, and enhancement update (Moderate)
CVE-2021-27922 medium 5.5 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-27921 medium 5.5 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-27923 medium 5.5 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-21295 medium 5.5 5y ago Possible request smuggling in HTTP/2 due missing validation
CVE-2021-28305 medium 5.5 5y ago An issue was discovered in the diesel crate before 1.4.6 for Rust. There is a use-after-free in the SQLite backend because the semantics of sqlite3_column_name are not followed.
CVE-2021-21306 medium 5.5 5y ago Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. Thi…
CVE-2021-21290 medium 5.5 5y ago Local Information Disclosure Vulnerability in Netty on Unix-Like systems
CVE-2021-21240 medium 5.5 5y ago httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which responds with long series of "\xa0" characters in the "www-authenticate" header…
CVE-2021-3715 medium 5.5 6y ago RHSA-2020:4609: kernel-rt security and bug fix update (Moderate)
CVE-2021-2007 medium 5.5 6y ago RHSA-2020:5503: mariadb-connector-c security, bug fix, and enhancement update (Moderate)
CVE-2021-47981 medium 5.4 5.4 14d ago Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription par…
CVE-2021-47955 medium 5.4 5.4 14d ago CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicious SVG files through the file upload functionality…
CVE-2021-47948 medium 5.4 5.4 21d ago WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject arbitrary HTML code by exploiting the Help Text field in payment forms. Attackers…
CVE-2021-47870 medium 5.4 5.4 4mo ago GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin attempts to sanitize user input using htmlspecialchars(), but this can be bypasse…
CVE-2021-47817 medium 5.4 5.4 4mo ago OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers can chain with a file upload to achieve remote code execution. Attackers can expl…
CVE-2021-45479 medium 5.4 5.4 3y ago Improper Neutralization of Input During Web Page Generation vulnerability in Yordam Information Technologies Library Automation System allows Stored XSS. This issue affects Library Automation System…
CVE-2021-47934 medium 5.3 5.3 14d ago MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and …
CVE-2021-47946 medium 5.3 5.3 21d ago OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthenticated attackers to modify victim account details by tricking users into visiti…
CVE-2021-45475 medium 5.3 5.3 4y ago Yordam Library Information Document Automation product before version 19.02 has an unauthenticated Information disclosure vulnerability.
CVE-2021-44795 medium 5.3 5.3 4y ago Single Connect does not perform an authorization check when using the "sc-assigned-credential-ui" module. A remote attacker could exploit this vulnerability to modify users permissions. The exploitat…
CVE-2021-44794 medium 5.3 5.3 4y ago Single Connect does not perform an authorization check when using the "sc-diagnostic-ui" module. A remote attacker could exploit this vulnerability to access the device information page. The exploita…
CVE-2021-44792 medium 5.3 5.3 4y ago Single Connect does not perform an authorization check when using the "log-monitor" module. A remote attacker could exploit this vulnerability to access the logging interface. The exploitation of thi…
CVE-2021-35556 medium 5.3 5.3 5y ago RHSA-2022:0345: java-1.8.0-ibm security update (Important)
CVE-2021-3806 medium 5.3 5.3 5y ago A path traversal vulnerability on Pardus Software Center's "extractArchive" function could allow anyone on the same network to do a man-in-the-middle and write files on the system.
CVE-2021-22764 medium 5.3 5.3 5y ago A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could…
CVE-2021-22897 medium 5.3 5.3 5y ago curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The s…
CVE-2021-31944 medium 5.0 5.0 5y ago 3D Viewer Information Disclosure Vulnerability
CVE-2021-45476 medium 4.7 4.7 4y ago Yordam Library Information Document Automation product before version 19.02 has an unauthenticated reflected XSS vulnerability.
CVE-2021-22701 medium 4.5 4.5 5y ago A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that c…
CVE-2021-47958 medium 4.3 4.3 15d ago CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG file…
CVE-2021-47953 medium 4.3 4.3 21d ago OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick a…