2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-4197HIGH7.8An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found i...
CVE-2021-4180MEDIUM4.3An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or ...
CVE-2021-4156HIGH7.1An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a speci...
CVE-2021-4150MEDIUM5.5A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker wi...
CVE-2021-4149MEDIUM5.5A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock op...
CVE-2021-4148MEDIUM5.5A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity ...
CVE-2021-3748HIGH7.5A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address ...
CVE-2021-3618HIGH7.4ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocol...
CVE-2021-3589HIGH8An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run...
CVE-2021-27476CRITICAL9.8A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection...
CVE-2021-27475HIGH8.6Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserializ...
CVE-2021-27474HIGH7.5Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS ...
CVE-2021-27473HIGH8.2Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccw...
CVE-2021-27472CRITICAL9.8A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre...
CVE-2021-27471HIGH8.6The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may all...
CVE-2021-27470CRITICAL9.8A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre ...
CVE-2021-27468CRITICAL9.8The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking p...
CVE-2021-27466CRITICAL9.8A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCen...
CVE-2021-27464CRITICAL9.8The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacki...
CVE-2021-27462CRITICAL9.8A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre ...
CVE-2021-27460CRITICAL9.8Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deseriali...
CVE-2021-27456LOW2.4Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-...
CVE-2021-27430MEDIUM6.8GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with phy...
CVE-2021-27428CRITICAL9.8GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervi...
CVE-2021-27426CRITICAL9.8GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Fac...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now