CVEs from 2021
Total
4,841
critical
critical 279
high
high 1,005
medium
medium 1,166
low
low 138
% Critical
5.8%
% with KEV
4.4%
% with exploit
5.3%
Top vendors
Top products
- office 13
- primavera_gateway 10
- weblogic_server 9
- modicon_m340_bmxp342020 8
- log4j 8
- primavera_unifier 8
- retail_service_backbone 7
- communications_unified_inventory_management 7
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-2471 | unknown | — | — | 4y ago | Incorrect Authorization in MySQL Connector Java | |||
| CVE-2021-3869 | unknown | — | — | 4y ago | Improper Restriction of XML External Entity Reference in Stanford CoreNLP | |||
| CVE-2021-3878 | unknown | — | — | 4y ago | Improper Restriction of XML External Entity Reference in Stanford CoreNLP | |||
| CVE-2021-21684 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins Git Plugin | |||
| CVE-2021-40824 | unknown | — | — | 4y ago | Logic error in Matrix SDK for Android | |||
| CVE-2021-40797 | unknown | — | — | 4y ago | An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authentic… | |||
| CVE-2021-21678 | unknown | — | — | 4y ago | Jenkins SAML Plugin allows bypassing CSRF protection for any URL | |||
| CVE-2021-21680 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins Nested View Plugin | |||
| CVE-2021-21677 | unknown | — | — | 4y ago | RCE vulnerability in Jenkins Code Coverage API Plugin | |||
| CVE-2021-21679 | unknown | — | — | 4y ago | Jenkins Azure AD Plugin allows bypassing CSRF protection for any URL | |||
| CVE-2021-21681 | unknown | — | — | 4y ago | Password stored in plain text by Jenkins Nomad Plugin | |||
| CVE-2021-40085 | unknown | — | — | 4y ago | An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value. | |||
| CVE-2021-38598 | unknown | — | — | 4y ago | OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending c… | |||
| CVE-2021-28490 | unknown | — | — | 4y ago | Cross-Site Request Forgery in OWASP CSRFGuard | |||
| CVE-2021-38155 | unknown | — | — | 4y ago | OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). … | |||
| CVE-2021-3642 | unknown | — | — | 4y ago | Observable Discrepancy in Wildfly Elytron | |||
| CVE-2021-33335 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers | |||
| CVE-2021-33338 | unknown | — | — | 4y ago | Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs | |||
| CVE-2021-33336 | unknown | — | — | 4y ago | Liferay Portal Journal Module and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) | |||
| CVE-2021-33339 | unknown | — | — | 4y ago | Liferay Portal Fragment Module and Liferay DXP Vulnerable to Cross-Site Scripting | |||
| CVE-2021-33337 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Document Library module | |||
| CVE-2021-35463 | unknown | — | — | 4y ago | Liferay Portal cross-site scripting (XSS) vulnerability in the Frontend Taglib module | |||
| CVE-2021-33326 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Frontend JS module | |||
| CVE-2021-33323 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP autosaves form data for other users to see | |||
| CVE-2021-33325 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Stores User Passwords in Cleartext | |||
| CVE-2021-33320 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP vulnerable to email spam via lack of flagging rate | |||
| CVE-2021-33321 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP insecure default configuration | |||
| CVE-2021-33328 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Edit Vocabulary Page | |||
| CVE-2021-33324 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Don't Check Permissions of Pages | |||
| CVE-2021-33332 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) | |||
| CVE-2021-33333 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Fails to Check User Permissions for Workflow Submissions | |||
| CVE-2021-33331 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Allows Arbitrary Redirect of Users to External URLs | |||
| CVE-2021-33334 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Fails to Properly Check User Permissions | |||
| CVE-2021-34802 | unknown | — | — | 4y ago | Improper Privilege Management in Neo4j Graph Database | |||
| CVE-2021-21674 | unknown | — | — | 4y ago | Missing permission check in Jenkins requests-plugin Plugin allows viewing pending requests | |||
| CVE-2021-21675 | unknown | — | — | 4y ago | CSRF vulnerabilities in Jenkins requests-plugin Plugin | |||
| CVE-2021-21673 | unknown | — | — | 4y ago | Open redirect vulnerability in Jenkins CAS Plugin | |||
| CVE-2021-21676 | unknown | — | — | 4y ago | Missing permission check in Jenkins requests-plugin Plugin allows sending emails | |||
| CVE-2021-31649 | unknown | — | — | 4y ago | JFinal Java Deserialization Vulnerability | |||
| CVE-2021-21669 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins Generic Webhook Trigger Plugin | |||
| CVE-2021-21663 | unknown | — | — | 4y ago | Missing permission check in Jenkins XebiaLabs XL Deploy Plugin allows capturing credentials | |||
| CVE-2021-21665 | unknown | — | — | 4y ago | CSRF vulnerability in Jenkins XebiaLabs XL Deploy Plugin allows capturing credentials | |||
| CVE-2021-21664 | unknown | — | — | 4y ago | Incorrect permission check in XebiaLabs XL Deploy Plugin allows capturing credentials | |||
| CVE-2021-20267 | unknown | — | — | 4y ago | A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersona… | |||
| CVE-2021-22118 | unknown | — | — | 4y ago | Improper Privilege Management in Spring Framework | |||
| CVE-2021-21657 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins Filesystem Trigger Plugin | |||
| CVE-2021-21658 | unknown | — | — | 4y ago | XML external entity vulnerability in Jenkins Nuget Plugin | |||
| CVE-2021-23937 | unknown | — | — | 4y ago | DNS based denial of service in Apache Wicket | |||
| CVE-2021-21660 | unknown | — | — | 4y ago | XSS vulnerability in Jenkins Markdown Formatter Plugin | |||
| CVE-2021-21659 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins URLTrigger Plugin | |||
| CVE-2021-25934 | unknown | — | — | 4y ago | OpenNMS Horizon vulnerable to XSS | |||
| CVE-2021-29043 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password | |||
| CVE-2021-29044 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Membership Request Admin Page | |||
| CVE-2021-29053 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Multiple SQL Injections | |||
| CVE-2021-29045 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the Redirect's Admin Page | |||
| CVE-2021-29046 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Asset Module Parameter | |||
| CVE-2021-29048 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in the Layout Admin Page | |||
| CVE-2021-29051 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Asset Publisher App | |||
| CVE-2021-29052 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Fails to Check Permissions | |||
| CVE-2021-29041 | unknown | — | — | 4y ago | Liferay DXP Vulnerable to Denial-of-service (DoS) in the Multi-Factor Authentication Module | |||
| CVE-2021-29047 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Fails to Invalidate CAPTCHA Answers After Use | |||
| CVE-2021-29040 | unknown | — | — | 4y ago | Liferay Portal and Liferay DXP Reveals Data via Overly Verbose Error Messages | |||
| CVE-2021-22137 | unknown | — | — | 4y ago | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch | |||
| CVE-2021-21643 | unknown | — | — | 4y ago | Incorrect permission checks in Jenkins Config File Provider Plugin allow enumerating credentials IDs | |||
| CVE-2021-21646 | unknown | — | — | 4y ago | Remote code execution vulnerability in Jenkins Templating Engine Plugin | |||
| CVE-2021-21645 | unknown | — | — | 4y ago | Missing permission checks in Jenkins Config File Provider Plugin allow enumerating configuration file IDs | |||
| CVE-2021-21647 | unknown | — | — | 4y ago | Missing permission check in Jenkins CloudBees CD Plugin allows scheduling builds | |||
| CVE-2021-21642 | unknown | — | — | 4y ago | XML External Entity Reference vulnerability in Jenkins Config File Provider Plugin | |||
| CVE-2021-21644 | unknown | — | — | 4y ago | CSRF vulnerability in Jenkins Config File Provider Plugin allows deleting configuration files | |||
| CVE-2021-22511 | unknown | — | — | 4y ago | SSL/TLS certificate validation unconditionally disabled by Jenkins Micro Focus Application Automation Tools Plugin | |||
| CVE-2021-22513 | unknown | — | — | 4y ago | Missing permission checks in Micro Focus Application Automation Tools Plugin | |||
| CVE-2021-22512 | unknown | — | — | 4y ago | CSRF vulnerability in Jenkins Micro Focus Application Automation Tools Plugin | |||
| CVE-2021-22510 | unknown | — | — | 4y ago | Reflected XSS vulnerability in Jenkins Micro Focus Application Automation Tools Plugin | |||
| CVE-2021-21641 | unknown | — | — | 4y ago | CSRF vulnerability in Jenkins promoted builds Plugin | |||
| CVE-2021-21634 | unknown | — | — | 4y ago | Passwords stored in plain text by Jenkins Jabber (XMPP) notifier and control Plugin | |||
| CVE-2021-21636 | unknown | — | — | 4y ago | Missing permission check in Jenkins Team Foundation Server Plugin allows enumerating credentials IDs | |||
| CVE-2021-21632 | unknown | — | — | 4y ago | Missing permission checks in Jenkins OWASP Dependency-Track Plugin allow capturing credentials | |||
| CVE-2021-21637 | unknown | — | — | 4y ago | Missing permission check in Jenkins Team Foundation Server Plugin allow capturing credentials | |||
| CVE-2021-21635 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins REST List Parameter Plugin | |||
| CVE-2021-21633 | unknown | — | — | 4y ago | CSRF vulnerability and in Jenkins OWASP Dependency-Track Plugin allow capturing credentials | |||
| CVE-2021-21631 | unknown | — | — | 4y ago | Missing permission check in Jenkins Cloud Statistics Plugin | |||
| CVE-2021-21628 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins Build With Parameters Plugin | |||
| CVE-2021-21630 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins Extra Columns Plugin | |||
| CVE-2021-21629 | unknown | — | — | 4y ago | CSRF vulnerability in Jenkins Build With Parameters Plugin | |||
| CVE-2021-21626 | unknown | — | — | 4y ago | Missing permission checks in Jenkins Warnings Next Generation Plugin allow listing workspace contents | |||
| CVE-2021-21624 | unknown | — | — | 4y ago | Incorrect permission checks in Jenkins Role-based Authorization Strategy Plugin may allow accessing some items | |||
| CVE-2021-21625 | unknown | — | — | 4y ago | Missing permission checks in Jenkins CloudBees AWS Credentials Plugin allows enumerating credentials IDs | |||
| CVE-2021-21627 | unknown | — | — | 4y ago | CSRF vulnerability in Jenkins Libvirt Agents Plugin | |||
| CVE-2021-21623 | unknown | — | — | 4y ago | Incorrect permission checks in Jenkins Matrix Authorization Strategy Plugin may allow accessing some items | |||
| CVE-2021-20218 | unknown | — | — | 4y ago | Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client | |||
| CVE-2021-21622 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins Artifact Repository Parameter Plugin | |||
| CVE-2021-21619 | unknown | — | — | 4y ago | XSS vulnerability in Jenkins Claim Plugin | |||
| CVE-2021-21621 | unknown | — | — | 4y ago | Support bundles can include user session IDs in Jenkins Support Core Plugin | |||
| CVE-2021-21616 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins Active Choices Plugin | |||
| CVE-2021-21617 | unknown | — | — | 4y ago | CSRF vulnerability in Jenkins Configuration Slicing Plugin | |||
| CVE-2021-21618 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins Repository Connector Plugin | |||
| CVE-2021-3396 | unknown | — | — | 4y ago | OpenNMS Horizon RCE via JEXL2 expression | |||
| CVE-2021-0341 | unknown | — | — | 4y ago | Square OkHttp can accept the wrong certificate | |||
| CVE-2021-21613 | unknown | — | — | 4y ago | XSS vulnerability in Jenkins TICS Plugin | |||
| CVE-2021-21612 | unknown | — | — | 4y ago | Credentials stored in plain text by Jenkins TraceTronic ECU-TEST Plugin |