2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-4197 | HIGH | 7.8 | 0.5% | Mar 23, 2022 | An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found i... |
| CVE-2021-4180 | MEDIUM | 4.3 | 0.8% | Mar 23, 2022 | An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or ... |
| CVE-2021-4156 | HIGH | 7.1 | 1.8% | Mar 23, 2022 | An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a speci... |
| CVE-2021-4150 | MEDIUM | 5.5 | 0.3% | Mar 23, 2022 | A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker wi... |
| CVE-2021-4149 | MEDIUM | 5.5 | 0.4% | Mar 23, 2022 | A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock op... |
| CVE-2021-4148 | MEDIUM | 5.5 | 0.3% | Mar 23, 2022 | A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity ... |
| CVE-2021-3748 | HIGH | 7.5 | 0.5% | Mar 23, 2022 | A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address ... |
| CVE-2021-3618 | HIGH | 7.4 | 2.0% | Mar 23, 2022 | ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocol... |
| CVE-2021-3589 | HIGH | 8 | 1.0% | Mar 23, 2022 | An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run... |
| CVE-2021-27476 | CRITICAL | 9.8 | 4.3% | Mar 23, 2022 | A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection... |
| CVE-2021-27475 | HIGH | 8.6 | 2.8% | Mar 23, 2022 | Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserializ... |
| CVE-2021-27474 | HIGH | 7.5 | 1.5% | Mar 23, 2022 | Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS ... |
| CVE-2021-27473 | HIGH | 8.2 | 0.8% | Mar 23, 2022 | Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccw... |
| CVE-2021-27472 | CRITICAL | 9.8 | 5.3% | Mar 23, 2022 | A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre... |
| CVE-2021-27471 | HIGH | 8.6 | 2.7% | Mar 23, 2022 | The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may all... |
| CVE-2021-27470 | CRITICAL | 9.8 | 3.7% | Mar 23, 2022 | A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre ... |
| CVE-2021-27468 | CRITICAL | 9.8 | 3.4% | Mar 23, 2022 | The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking p... |
| CVE-2021-27466 | CRITICAL | 9.8 | 3.7% | Mar 23, 2022 | A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCen... |
| CVE-2021-27464 | CRITICAL | 9.8 | 3.3% | Mar 23, 2022 | The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacki... |
| CVE-2021-27462 | CRITICAL | 9.8 | 3.7% | Mar 23, 2022 | A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre ... |
| CVE-2021-27460 | CRITICAL | 9.8 | 3.1% | Mar 23, 2022 | Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deseriali... |
| CVE-2021-27456 | LOW | 2.4 | 0.2% | Mar 23, 2022 | Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-... |
| CVE-2021-27430 | MEDIUM | 6.8 | 0.2% | Mar 23, 2022 | GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with phy... |
| CVE-2021-27428 | CRITICAL | 9.8 | 1.2% | Mar 23, 2022 | GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervi... |
| CVE-2021-27426 | CRITICAL | 9.8 | 1.2% | Mar 23, 2022 | GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Fac... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now