CVE Vulnerabilities in 2021

61 documented vulnerabilities published in 2021.

Other years: 2026 2025 2024 2023 2022 2020

Top Affected Vendors in 2021

All CVEs from 2021

CVE-2021-44832
6.6 medium

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is f

Apache Log4J Dec 28, 2021
CVE-2021-45450
7.5 high

In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.

Trustedfirmware Mbed Tls Dec 21, 2021
CVE-2021-44732
9.8 critical

Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.

Arm Mbed Tls Dec 20, 2021
CVE-2021-45105
5.9 medium

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was

Apache Log4J Dec 18, 2021
CVE-2021-43875
7.8 high

Microsoft Office Graphics Remote Code Execution Vulnerability

Microsoft 365 Apps Dec 15, 2021
CVE-2021-43256
7.8 high

Microsoft Excel Remote Code Execution Vulnerability

Microsoft 365 Apps Dec 15, 2021
CVE-2021-43255
5.5 medium

Microsoft Office Trust Center Spoofing Vulnerability

Microsoft 365 Apps Dec 15, 2021
CVE-2021-42295
5.5 medium

Visual Basic for Applications Information Disclosure Vulnerability

Microsoft 365 Apps Dec 15, 2021
CVE-2021-42293
6.5 medium

Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability

Microsoft 365 Apps Dec 15, 2021
CVE-2021-4104
7.5 high

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote

Apache Log4J Dec 14, 2021
CVE-2021-44149
7.8 high

An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-related registers, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operat

Trustedfirmware Op-Tee Dec 7, 2021
CVE-2021-36133
7.1 high

The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a DMA capable peripheral.

Trustedfirmware Op-Tee Dec 7, 2021
CVE-2021-4019
7.8 high

vim is vulnerable to Heap-based Buffer Overflow

Neovim Neovim Dec 1, 2021
CVE-2021-42296
7.8 high

Microsoft Word Remote Code Execution Vulnerability

Microsoft 365 Apps Nov 10, 2021
CVE-2021-35556
5.3 medium

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated att

Oracle Graalvm Oct 20, 2021
CVE-2021-25740
3.1 low

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

Kubernetes Kubernetes Sep 20, 2021
CVE-2020-8561
4.1 medium

A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log l

Kubernetes Kubernetes Sep 20, 2021
CVE-2016-20012
5.3 medium

OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: t

Openbsd Openssh Sep 15, 2021
CVE-2021-22792
7.5 high

A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (p

Schneider-Electric Modicon M340 Bmxp341000 Sep 2, 2021
CVE-2021-22791
6.5 medium

A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part n

Schneider-Electric Modicon M340 Bmxp341000 Sep 2, 2021
CVE-2021-22790
6.5 medium

A CWE-125: Out-of-bounds Read vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part nu

Schneider-Electric Modicon M340 Bmxp341000 Sep 2, 2021
CVE-2021-22789
6.5 medium

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP

Schneider-Electric Modicon M340 Bmxp341000 Sep 2, 2021
CVE-2019-25052
9.1 critical

In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, causing a crash that could leak sensitive information.

Trustedfirmware Op-Tee Aug 11, 2021
CVE-2021-22926
7.5 high

libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Transport, an application can ask for the client certif

Haxx Curl Aug 5, 2021