CVEs from 2021

6,258 normalized CVEs published or assigned in this year.

Total
6,258
critical
critical 272
high
high 976
medium
medium 1,141
low
low 135
% Critical
4.3%
% with KEV
3.4%
% with exploit
3.4%

Top products

  • office 13
  • 365_apps 6
  • office_long_term_servicing_channel 6
  • library_automation_system 5
  • single_connect 4
  • http_server 3
  • solidfire 2
  • student_information_management_system 2
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2021-22054 unknown 1.5 3mo ago Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send …
CVE-2021-22681 unknown 1.5 3mo ago Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controll…
CVE-2021-22175 unknown 1.5 3mo ago GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
CVE-2021-26828 unknown 1.5 6mo ago OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
CVE-2021-26829 unknown 1.5 6mo ago OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.
CVE-2021-43226 unknown 1.5 8mo ago Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.
CVE-2021-32030 unknown 1.5 1y ago ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The impacted products c…
CVE-2021-20035 unknown 1.5 1y ago SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, whic…
CVE-2021-44207 unknown 1.5 1y ago Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be …
CVE-2021-40407 unknown 1.5 2y ago Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.
CVE-2021-41277 unknown 1.5 2y ago Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.
CVE-2021-26086 unknown 1.5 2y ago Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.
CVE-2021-20124 unknown 1.5 2y ago Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download a…
CVE-2021-20123 unknown 1.5 2y ago Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the un…
CVE-2021-31196 unknown 1.5 2y ago Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.
CVE-2021-33044 unknown 1.5 2y ago Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication.
CVE-2021-33045 unknown 1.5 2y ago Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.
CVE-2021-40655 unknown 1.5 2y ago D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page.
CVE-2021-44529 unknown 1.5 2y ago Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
CVE-2021-36380 unknown 1.5 2y ago Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in …
CVE-2021-29256 unknown 1.5 3y ago Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information. suse
CVE-2021-25394 unknown 1.5 3y ago Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.
CVE-2021-25487 unknown 1.5 3y ago Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution…
CVE-2021-25372 unknown 1.5 3y ago Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access.
CVE-2021-25489 unknown 1.5 3y ago Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic.
CVE-2021-25371 unknown 1.5 3y ago Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP.
CVE-2021-25395 unknown 1.5 3y ago Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.
CVE-2021-44026 unknown 1.5 3y ago Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. debian
CVE-2021-27877 unknown 1.5 3y ago Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.
CVE-2021-27878 unknown 1.5 3y ago Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.
CVE-2021-27876 unknown 1.5 3y ago Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Ag…
CVE-2021-30900 unknown 1.5 3y ago Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges.
CVE-2021-35587 unknown 1.5 4y ago Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.
CVE-2021-25337 unknown 1.5 4y ago Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with …
CVE-2021-25369 unknown 1.5 4y ago Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This …
CVE-2021-25370 unknown 1.5 4y ago Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. …
CVE-2021-3493 unknown 1.5 4y ago The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation. susedebian
CVE-2021-31010 unknown 1.5 4y ago In affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions.
CVE-2021-38406 unknown 1.5 4y ago Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) resulting in an out-of-bounds write that allows for code exec…
CVE-2021-30983 unknown 1.5 4y ago Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges.
CVE-2021-38163 unknown 1.5 4y ago SAP NetWeaver contains a vulnerability that allows unrestricted file upload.
CVE-2021-30883 unknown 1.5 4y ago Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution.
CVE-2021-1048 unknown 1.5 4y ago Android kernel contains a use-after-free vulnerability that allows for privilege escalation. susedebian
CVE-2021-40450 unknown 1.5 4y ago Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-41357 unknown 1.5 4y ago Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-22600 unknown 1.5 4y ago Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly fo… susedebian
CVE-2021-42278 unknown 1.5 4y ago Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-27852 unknown 1.5 4y ago Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.
CVE-2021-39793 unknown 1.5 4y ago Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.
CVE-2021-42287 unknown 1.5 4y ago Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-31166 unknown 1.5 4y ago Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
CVE-2021-45382 unknown 1.5 4y ago A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.
CVE-2021-34484 unknown 1.5 4y ago Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-28799 unknown 1.5 4y ago QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
CVE-2021-21551 unknown 1.5 4y ago Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
CVE-2021-38646 unknown 1.5 4y ago Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
CVE-2021-20028 unknown 1.5 4y ago SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
CVE-2021-26085 unknown 1.5 4y ago Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
CVE-2021-34486 unknown 1.5 4y ago Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.
CVE-2021-22941 unknown 1.5 4y ago Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.
CVE-2021-42237 unknown 1.5 4y ago Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
CVE-2021-21973 unknown 1.5 4y ago VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.
CVE-2021-41379 unknown 1.5 4y ago Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-36934 unknown 1.5 4y ago If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.
CVE-2021-20038 unknown 1.5 4y ago SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.
CVE-2021-35247 unknown 1.5 4y ago SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.
CVE-2021-25297 unknown 1.5 4y ago Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-40870 unknown 1.5 4y ago Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
CVE-2021-25296 unknown 1.5 4y ago Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-22991 unknown 1.5 4y ago The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.
CVE-2021-25298 unknown 1.5 4y ago Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-21975 unknown 1.5 4y ago Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to s…
CVE-2021-33766 unknown 1.5 4y ago Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.
CVE-2021-27860 unknown 1.5 4y ago A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.
CVE-2021-36260 unknown 1.5 4y ago A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
CVE-2021-22017 unknown 1.5 4y ago Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.
CVE-2021-43890 unknown 1.5 5y ago Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.
CVE-2021-45046 unknown 1.5 5y ago Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in… debiansusejava
CVE-2021-44168 unknown 1.5 5y ago Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.
CVE-2021-44515 unknown 1.5 5y ago Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.
CVE-2021-35394 unknown 1.5 5y ago RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution.
CVE-2021-44077 unknown 1.5 5y ago Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution
CVE-2021-37415 unknown 1.5 5y ago Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication
CVE-2021-42292 unknown 1.5 5y ago A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.
CVE-2021-40449 unknown 1.5 5y ago Unspecified vulnerability allows for an authenticated user to escalate privileges.
CVE-2021-42321 unknown 1.5 5y ago An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
CVE-2021-34473 unknown 1.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-20023 unknown 1.5 5y ago SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Se…
CVE-2021-36948 unknown 1.5 5y ago Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-1879 unknown 1.5 5y ago Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability cou…
CVE-2021-1497 unknown 1.5 5y ago Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.
CVE-2021-30869 unknown 1.5 5y ago Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.
CVE-2021-1647 unknown 1.5 5y ago Microsoft Defender contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-30713 unknown 1.5 5y ago Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences.
CVE-2021-28550 unknown 1.5 5y ago Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
CVE-2021-21972 unknown 1.5 5y ago VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrest…
CVE-2021-27102 unknown 1.5 5y ago Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.
CVE-2021-27562 unknown 1.5 5y ago Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure fun…
CVE-2021-28664 unknown 1.5 5y ago Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt…
CVE-2021-36942 unknown 1.5 5y ago Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to au…