CVE Vulnerabilities in 2021

61 documented vulnerabilities published in 2021.

Other years: 2026 2025 2024 2023 2022 2020

Top Affected Vendors in 2021

All CVEs from 2021

CVE-2021-29241
7.5 high

CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).

Codesys Control For Beaglebone Sl May 3, 2021
CVE-2021-22659
8.6 high

Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allowing the attacker to retrieve or modify random values in the register. If successfully exploited, this may lead to a buffer overflow resulting in a den

Rockwellautomation Micrologix 1400 Firmware Mar 25, 2021
CVE-2021-25667
8.8 high

A vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions >= V4.3 and < V6.4), SCALANCE S615 (All versions >= V4.3 and < V6.4), SCALANCE SC-600 Family (All versions >= V2.0 and < V2.1.3), SCALANCE XB-200 (All versions < V4.1), SCALANCE XC

Siemens Ruggedcom Rm1224 Firmware Mar 15, 2021
CVE-2021-22713
7.5 high

A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security notifcation for affected versions), which could cause the meter to reboot.

Schneider-Electric Powerlogic Ion8650 Firmware Mar 11, 2021
CVE-2021-21974
8.8 high

OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in

Vmware Cloud Foundation Feb 24, 2021
CVE-2021-22703
7.5 high

A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor intercepts HTTP

Schneider-Electric Powerlogic Ion7400 Firmware Feb 19, 2021
CVE-2021-22702
7.5 high

A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/73xx, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor i

Schneider-Electric Powerlogic Ion7400 Firmware Feb 19, 2021
CVE-2021-22701
4.5 medium

A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to perform an unintended action on the target device when using the HTTP web interf

Schneider-Electric Powerlogic Ion7400 Firmware Feb 19, 2021
CVE-2020-15798
9.8 critical

A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (All versions), SINAMICS GL150 (with option X30) (All versions), SINAMICS GM150 (with option X30) (Al

Siemens Simatic Hmi Comfort Panels Firmware Feb 9, 2021
CVE-2020-8554
6.3 medium

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typicall

Kubernetes Kubernetes Jan 21, 2021
CVE-2020-27283
5.3 medium

An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arbitrary memory locations.

Redlion Crimson Jan 6, 2021
CVE-2020-27279
7.5 high

A NULL pointer deference vulnerability has been identified in the protocol converter. An attacker could send a specially crafted packet that could reboot the device running Crimson 3.1 (Build versions prior to 3119.001).

Redlion Crimson Jan 6, 2021
CVE-2020-27285
9.1 critical

The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication.

Redlion Crimson Jan 6, 2021